It has a clear MIT license, tests, and a small dependency set. The repository is not archived and is backed by an organization, but its minimal README limits consumer guidance.
58%
Total Score
75
100
75
75
The artifact includes tests and a README, but the README is only 14 characters and the project has no changelog. Tests are a positive maintenance signal; the minimal documentation still weakens consumer transparency.
The package has made six releases since July 2024, but none in the last 12 months; the latest release was about 17 months ago. This is a meaningful maintenance concern despite the earlier roughly monthly cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. That raises abandonment risk, though the repository is not archived.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations unspecified. This is a transparency gap, not evidence of a security defect.
All six analyzed action references are unpinned, so workflow behavior can change without a package release. The audit found no dangerous triggers, untrusted checkouts, script injection, or other findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imedge/json Version >=0.1 | — | — |
ramsey/uuid Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.