Clear licensing, documentation, and release notes make integration easier. The small release history and workflow hygiene leave less evidence of ongoing maintenance, so pinning version 2.0.0 is prudent.
62%
Total Score
75
100
88
75
The package has only three releases over about 715 days, with one release in the last 12 months and a median interval of about 273 days. This indicates a small and infrequent maintenance cadence.
The repository recorded zero commits and zero active maintainers in the past three months. Although a recent release exists, this provides limited evidence of current development capacity.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. The missing automated security coverage is a maintenance hygiene concern, not evidence that the package is unsafe.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations.
All three workflows were analyzed, but all 11 action references are unpinned; two high-confidence medium-severity secrets-inherit findings also pass credentials to reusable workflows, and one workflow has top-level write permissions. These are meaningful supply-chain hygiene weaknesses, although no untrusted checkout or script-injection path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
formal/orm Version ~6.0 | — | — |
innmind/foundation Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.