A single individual maintains the package, and the workflow leaves four actions unpinned. Its tests, MIT license, static analysis, and unarchived repository provide useful safeguards, but ongoing ownership looks thin.
55%
Total Score
50
93
50
Only one registry account has publishing access, leaving limited visible publishing capacity. The repository is user-owned, so there is no organizational backing signal to compensate for that thin base.
The latest release was published on May 16, 2024, with no releases in the last 12 months, so maintenance appears stalled for more than two years. The package has nine releases over a long history, which shows it is established but does not offset the current pause.
The repository had zero commits and zero active maintainers in the last three months, consistent with more than two years since the last push. This is meaningful abandonment risk for a library dependency.
No repository security policy was found, leaving vulnerability-reporting guidance unclear. This is a modest transparency gap rather than a severe dependency risk.
The only workflow was fully analyzed with no untrusted checkouts or injection findings, but all four action references are unpinned. Missing top-level permissions is acceptable on its own; the unpinned actions remain a small reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
emonkak/database Version ^2.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
emonkak/enumerable Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.