The linked project remains unarchived and has a clear README, license, and release notes. Its registry history is stale, and the workflow uses an archived action.
55%
Total Score
50
86
100
The package has only one release, published in November 2020, with no releases in the last 12 months. That makes the registry artifact stale despite the repository having a later push.
There were no commits or active maintainers in the last three months. Combined with the absent recent registry releases, this leaves current maintenance uncertain.
The assessed version is marked prerelease, and all recent versions are prereleases. This adds some versioning uncertainty for a dependency with an otherwise stable major version.
The only workflow was fully analyzed and has no untrusted checkout or script-injection findings, but all four action references are unpinned and one uses an archived action. This is a real, limited supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mariusbuescher/node-composer Version >1.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.