Workflow credentials are broader than needed and all five actions are unpinned. The project still has a recent release, documentation, tests, and an unarchived organizational repository.
68%
Total Score
75
86
75
The package has existed since 2017, but only one release appeared in the last 12 months and releases are typically about 237 days apart. The latest release is recent, so this indicates a slow rather than abandoned cadence.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release and unarchived repository provide some counterevidence.
The repository uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. That makes vulnerability reporting less clear for a package intended for dependency use.
All five analyzed action references are unpinned, and both workflows inherit secrets with high-confidence medium-severity findings. The audit was complete and found no untrusted checkouts or script injection, limiting this to a workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
innmind/foundation Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.