It includes tests, a clear README, release notes, and a stable 1.2.0 version, with no install-time scripts. The small repository also uses Dependabot, but its nine GitHub Actions references are unpinned and there is no security policy.
58%
Total Score
50
88
83
The latest release was published about six years ago, and there were no releases in the preceding 12 months. This is a substantial maintenance concern for a deployment library, despite its stable release history and three total releases.
The repository recorded no commits and no active maintainers in the last three months; its last push was about two years ago. That suggests ongoing maintenance capacity is limited, although the repository is not archived.
All three workflows were analyzed successfully with no dangerous triggers, sinks, or audit findings, but all nine action references are unpinned. The clean audit is reassuring, while unpinned actions leave avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/console Version ^4.0 || ^5.0 | — | — |
symfony/process Version ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.