Recent releases, tests, and a clear license provide useful maintenance evidence, but repository commits stopped in the last three months and all six workflow actions are unpinned. Use gomzyakov/code-style instead.
22%
Total Score
50
79
50
Packagist marks the package abandoned and provides gomzyakov/code-style as a replacement. This is a direct release-selection risk even though the repository remains active.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens confidence in ongoing maintenance, although the recent release history provides some counterweight.
The repository name does not match the package name and its README does not mention this package. That weakens confidence that the linked repository is the exact package source rather than a renamed or shared project.
The repository has no security policy. For a small developer-tool package this is a transparency gap, though Dependabot-based scanning provides some compensating security practice.
All three workflows were analyzed without high-confidence findings or dangerous triggers, but all six action references are unpinned. That leaves avoidable build-integrity and reproducibility exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.