The repository includes tests, a clear BSD-3-Clause license, and release notes for this version. All three workflow actions are unpinned, and no security policy is published.
64%
Total Score
75
93
75
The package has only four releases and none in the last three years, indicating a slow release cadence and possible abandonment risk despite the repository remaining active recently.
There were no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance even though the repository's recorded push date is more recent.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities in a package that integrates with an external API.
The audit completed cleanly with no injection or high-severity findings, but all 3 of 3 action references are unpinned, leaving build behavior exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
calcinai/xero-php Version ^2.5.5 | — | — |
silverstripe/framework Version ^5 | — | — |
symbiote/silverstripe-queuedjobs Version ^4 || ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.