The package is licensed, documented, and backed by repository tests plus release notes for this version. Its workflow leaves all 13 actions unpinned, and no commits appeared in three months, so build reproducibility and maintenance deserve attention.
68%
Total Score
83
100
88
50
The package has existed since December 2013 with 19 releases, but it had no releases in the last 12 months before this assessment. That suggests a slower release cadence, though the current version is stable and documented.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, partially offset by the recent repository push and the documented release.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, although the package is small and has a limited runtime dependency surface.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 13 action references are unpinned, weakening build reproducibility; the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.