The MIT license, small dependency surface, and included tests reduce adoption friction. Unpinned workflow actions and no security policy leave maintenance hygiene weaker.
60%
Total Score
75
100
88
75
Only two releases were published, with the latest on January 20, 2023 and none in the past 12 months. This indicates a long release gap for a dependency that may still require compatibility maintenance.
There were no commits or active maintainers in the three months measured. Combined with the absence of releases in the past 12 months, this raises concern about current maintenance capacity.
The repository uses Make and Composer for build tasks, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three analyzed workflow actions are unpinned, so workflow inputs can change without a repository commit. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, which limits the severity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.