Clear documentation, tests, release notes, and a stable release history support adoption. Recent repository work has stopped, while workflow references are unpinned and reusable workflows inherit secrets, leaving maintenance and build-hygiene concerns.
68%
Total Score
75
100
89
83
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that current maintenance may have slowed despite the broader release history.
Five stars and no forks show a small user and contributor footprint. Popularity is only supporting evidence, but this limited external base provides little resilience if the primary maintainer stops work.
The project uses Make and Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not evidence that the release is unsafe.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations for a framework package.
All six analyzed action references are unpinned, which weakens build reproducibility, and all three workflows have high-confidence secrets-inherit findings; one workflow also grants top-level write permissions. No dangerous trigger or untrusted checkout sink was found, so this is workflow hygiene risk rather than a severe standalone issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/di Version ~3.0 | — | — |
innmind/foundation Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.