The package includes tests, a useful README, a matching repository, and read-only workflow permissions. However, there has been no recorded commit or release activity for over two years, and all three workflow actions are unpinned; the single-maintainer project also has no security policy.
58%
Total Score
50
90
67
The package has six releases, but none in the last 12 months and the latest was published over two years ago, indicating a likely inactive release stream.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and raising maintenance risk.
The repository has no security policy. This is a transparency and response-process gap, although the package has a matching source repository and no other severe workflow findings.
The workflow was fully analyzed, uses read-only permissions, and has no detected dangerous findings, but all three action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/event-loop Version ^1.4.0 | — | — |
laravel/serializable-closure Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.