The package has a clear Apache-2.0 license, extensive README documentation, repository tests, and a long release history. Its small dependency footprint and organization-backed repository support adoption, though workflow hardening and security documentation would improve confidence.
65%
Total Score
67
100
94
50
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release and longer project history provide some compensation.
There were no new or closed issues or pull requests in the last month, suggesting limited current interaction, but the available activity window is short and does not establish abandonment by itself.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy. That weakens vulnerability-reporting transparency for a database query library, though it does not by itself indicate abandonment.
All 17 analyzed action references are unpinned, which weakens build reproducibility. The audit also found a high-confidence template-injection pattern, but no untrusted checkout or script-injection sink was reported, so it remains a workflow hygiene concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.