Clear documentation, tests, licensing, and dependency tooling support adoption. Maintenance activity is currently quiet, while workflow checks need attention before treating releases as strongly managed.
64%
Total Score
75
100
93
75
The package has 11 releases over about four years, but no releases in the last 12 months; this lowers confidence in ongoing maintenance without indicating abandonment on its own.
The repository recorded zero commits and zero active maintainers in the last three months. A recent repository push is compensating evidence that it is not archived, but current development activity remains quiet.
The repository has no published security policy. This is a transparency gap, but it is moderate because the project does use Dependabot scanning.
All three workflows were analyzed successfully, but all 8 action references are unpinned and a high-confidence bot-conditions finding reports spoofable actor context. There are no untrusted checkouts or script-injection findings, limiting the risk to workflow hygiene rather than a severe release threat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sunrise/http-router Version ^3 | — | — |
imponeer/smarty-extensions-contracts Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.