The package includes a license, consumer documentation, repository tests, and release notes for this version. Its small dependency set and inactive install scripts limit extra complexity, but workflow references are not pinned and no security policy is provided.
42%
Total Score
50
100
75
67
Only two releases were published, both in October 2022, with no release in the subsequent years. This is strong evidence of abandonment risk for a monitoring component.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release. This materially lowers confidence in ongoing fixes.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a maintenance and transparency gap, but it does not outweigh the direct evidence of inactivity by itself.
The assessed release is v2.1.0-beta2, and all recent releases are prereleases. That leaves production compatibility and future maintenance less certain.
All four workflows were analyzed without dangerous triggers or audit findings, but all four action references are unpinned. That is a supply-chain hygiene weakness, though not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
imiphp/imi-meter Version ~2.1.0 | — | — |
promphp/prometheus_push_gateway_php Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.