The release includes documentation, tests, a license, and notes for this version. Maintenance is concentrated in one contributor, and workflow references are unpinned; recent activity does not offset the registry withdrawal.
24%
Total Score
50
86
50
Packagist marks the entire package as abandoned, with no distinct replacement identified because the listed replacement is the same package. This is a severe adoption and continuity risk despite other recent activity.
All recent commits came from one contributor, giving the project a single-person maintenance dependency. The repository is user-owned, so no organizational handoff evidence compensates for that concentration.
The repository had 2 commits in the last 3 months, showing some recent activity, but the volume is limited and does not by itself demonstrate strong maintenance capacity.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, although it is less severe than the package-level abandonment status.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned. Missing top-level permissions is acceptable here and is not a concern on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.