The package is MIT-licensed, tested, and tied to an organization-owned repository. Its only release was 752 days ago, recent commit activity is absent, and the workflow leaves all three actions unpinned without security scanning or a security policy.
58%
Total Score
75
83
50
This is the sole release, published 752 days ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance, although the repository was pushed later and is not archived.
The repository recorded zero commits and zero active maintainers in the last 3 months. This supports an abandonment concern, though the package may be intentionally stable.
The repository uses Make and Composer, showing basic build tooling, but no security scanning tools were detected. That is a transparency and maintenance weakness.
No security policy was found in the repository. This is a minor transparency gap, especially alongside the absence of security scanning.
All three analyzed action references are unpinned, weakening build reproducibility and update safety. The audit was complete and found no untrusted checkout, injection, or high-severity workflow issue; the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fond-of-kudu/kletties Version ^1.0.0 | — | — |
fond-of-oryx/jellyfish-sales-order-extension Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.