The package has a clear MIT license, tests, and an organization-backed repository. Its workflow leaves all three actions unpinned, adding avoidable release hygiene risk.
62%
Total Score
75
100
88
75
Only two releases exist, and the latest was published in January 2023, about 3 years and 8 months before collection, with no releases in the last 12 months. This is a meaningful maintenance concern.
There were no commits or active maintainers in the three months before collection. The January 2025 push partly offsets this, but current maintenance capacity remains uncertain.
Make and Composer provide build tooling, but no security scanning tools were detected. This is a modest process gap rather than evidence of abandonment.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though this alone does not make the package unfit.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, and it does not grant top-level write permissions. However, all three action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.