A single active contributor leaves maintenance dependent on one person, while the workflow uses four unpinned actions. The package is documented, licensed, tested in the repository, and has no install-time scripts.
67%
Total Score
50
90
50
The package has 18 releases over about 20 months, but only one release in the last 12 months; this indicates substantially slower recent delivery despite an earlier rapid cadence.
All recent commits came from one contributor, so maintenance continuity depends entirely on that person; the repository is user-owned rather than organization-backed.
The repository had one commit from one active maintainer in the last three months, showing limited recent development activity.
The repository has no security policy, which reduces the project's vulnerability-reporting transparency; this is a hygiene gap rather than evidence of abandonment on its own.
The workflow was fully analyzed, uses read-only permissions, and has no detected dangerous sinks or audit findings. However, all four referenced actions are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
monolog/monolog Version ^3.9 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
illuminate/collections Version ^12.36 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.