Tests, release notes, and organization backing improve transparency. The repository has no commits in three months, while both workflow actions are unpinned and no security policy is provided. The small, focused dependency set and readme reduce adoption friction.
68%
Total Score
75
83
75
This is a brand-new package with one release and no established release cadence, so maintenance maturity cannot yet be demonstrated.
The repository recorded zero commits and zero active maintainers in the last three months. Because this is a first release, that may reflect its recent creation, but it still leaves ongoing maintenance unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
No security policy is present, which makes vulnerability reporting and response expectations less transparent for a package intended to be depended on.
The workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings. However, both of its two action references are unpinned, so their resolved code can change over time.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
elephentity/runtime Version ^0.10 || ^0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.