The package has a clear README, matching repository, tests, and an explicit BSD-3-Clause license. Its small dependency surface and organization ownership help, but ongoing maintenance evidence is limited.
57%
Total Score
75
100
88
50
The package has 8 releases since February 2015, but none in the last 12 months and the latest release was in April 2022, over four years ago. This is a meaningful maintenance concern despite the historically regular release intervals.
There were no commits and no active maintainers during the last three months. Combined with the old latest registry release, this supports a real concern about current maintenance capacity.
The repository uses Composer and Make, showing established build tooling, but no security scanning tools were detected. The tooling is adequate for the project, with a modest security-process gap.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it is not evidence that the package is unsafe by itself.
All 8 analyzed action references are unpinned, so workflow dependencies can change without a reviewed commit; this is a supply-chain hygiene concern. The audit analyzed all 3 workflows and found no untrusted checkout, script injection, dangerous trigger, or other reported finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
icanboogie/render Version ^0.7|^0.8 | — | — |
icanboogie/icanboogie Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.