Usable release with an MIT license declaration and a recent registry release, but the project looks quiet (no commits/issues recently) and the CI audit shows unpinned GitHub Action uses. Pin/verify the workflow inputs if you adopt this now.
65%
Total Score
50
75
The artifact itself lacks a readme, tests, and changelog, which can hurt consumer self-service, even if the repository contains tests. The missing changelog/readme in the published artifact is a real usability/maintainer-information gap.
There were zero commits in the last 3 months and zero active maintainers detected in that window, which raises abandonment/slow-maintenance risk despite the older recent release.
The version is not treated as a stable major (consistent with a 0.x line) even though it is not marked as a prerelease. That’s normal for early-stage libraries, but it keeps the risk profile from looking fully mature.
The audit found no direct high-risk workflow findings, but it reports 9/9 GitHub Action uses as unpinned, which increases supply-chain risk for CI execution. The “action definitions analyzed” count is 0, so treat the audit as hygiene rather than definitive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.