It has an MIT license, a readable package, recent release notes, and a small runtime dependency surface. Maintenance safeguards are incomplete: there are no tests, no security policy, and all four workflow actions are unpinned.
12%
Total Score
75
100
75
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct indication that depending on it carries substantial abandonment risk.
The linked source repository is archived, even though it was last pushed on January 8, 2026. An archived repository is a severe maintenance and support risk for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months. This reinforces the abandonment concern rather than showing ongoing maintenance capacity.
The repository has no published security policy. For a package intended to run in a project, this reduces transparency about vulnerability reporting and handling.
The sole workflow was fully analyzed, scopes permissions at job level, and has no untrusted checkout or script-injection findings. However, all four action references are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
helsingborg-stad/acf-export-manager Version >=1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.