The package is clearly identified, licensed, and supported by a focused repository with tests. Its workflow is fully audited, but the project lacks a published security policy and does not pin its action dependencies.
63%
Total Score
50
92
67
There have been only two releases over about 28 months, with one release in the last year and a median interval of roughly 20 months. This indicates a slow maintenance cadence, though the latest release is recent enough to show the project is not abandoned outright.
The repository recorded no commits and had no active maintainers during the last 3 months. With no stronger recent activity signal to offset it, this raises maintenance and abandonment concerns.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a meaningful but not severe gap for a small cache library.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both referenced actions are unpinned, leaving a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
webmozart/assert Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.