It has a clear BSD license, tests, changelog, and no install scripts. The small dependency footprint and organization backing help, but unpinned workflow actions add maintenance hygiene risk.
62%
Total Score
75
100
79
100
This is the package's only release, published about 5 months ago, so there is not yet enough history to demonstrate sustained maintenance.
There were no commits and no active maintainers in the last 3 months, which is concerning for a new prerelease because ongoing maintenance has not yet been demonstrated.
The repository uses Make and Composer, but no security scanning tools were detected, leaving a modest security-process gap.
The latest version is 1.0.0-alpha and every recent release is a prerelease, which signals an immature API and higher change risk for consumers.
All four analyzed workflow actions are unpinned, so builds may resolve changing action revisions; the audit found no dangerous triggers, untrusted checkouts, script injection, or other findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
poliander/cron Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.