The codebase includes tests, a MIT license, and no install-time scripts, with organization backing and a matching repository. Maintenance has stopped for about two years, and workflow dependencies are all unpinned, so long-term support and build reproducibility are concerns.
54%
Total Score
75
90
100
The latest release was about two years ago, with no releases in the last 12 months; this is meaningful abandonment risk despite eight releases since the project began.
The repository had no commits and no active maintainers in the last three months, reinforcing the concern that maintenance has stopped.
All six referenced GitHub Actions uses are unpinned, weakening build reproducibility; however, all three workflows were analyzed, had no untrusted checkout or injection findings, and had no top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
imedge/systemd Version >=0.2 | — | — |
amphp/byte-stream Version ^2.1 | — | — |
imedge/cli-screen Version >=0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.