Clear documentation, tests, licensing, and an established release record support adoption. Pin the unpinned workflow image and confirm maintenance resumes before relying on it for long-lived infrastructure.
68%
Total Score
75
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months. Recent releases partly compensate for that gap, but the current lack of source activity raises maintenance risk.
Composer build tooling is present, but no security scanning tools were detected. The repository's security policy provides some transparency, so this is a limited hygiene concern rather than a severe maintenance risk.
Both workflows were analyzed and have no untrusted checkouts or script injection, but all four action references are unpinned and the audit found a high-confidence unpinned container image. This weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 | — | — |
laravel/framework Version ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
elasticsearch/elasticsearch Version ^8.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.