A single maintainer and no commits in the last three months limit ongoing maintenance capacity. The repository remains active in structure, licensed, tested, and not archived, but workflow hygiene needs attention.
58%
Total Score
67
100
94
50
One registry maintainer is a limited publishing base, though the repository is organization-owned, making the short registry list less concerning than it would be for an individual project.
The latest release was over three years ago, with no releases in the last 12 months; the six-release history shows the package is stable but not actively evolving.
There were no commits and no active maintainers in the last three months, a concrete sign that maintenance has currently stalled.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All workflows were analyzed, but all five action references are unpinned and the audit found high-confidence bot-condition and unpinned-image issues; these are workflow hygiene risks rather than direct evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.