The source repository remains active, with three contributors making recent commits and tests present in the repository. Its workflow enables insecure commands and leaves all three action references unpinned, adding supply-chain maintenance concerns.
42%
Total Score
100
71
75
Packagist marks the package abandoned at package scope, even though the listed replacement is the same package; this is a direct warning against new dependency adoption.
The package has 38 releases since 2014, but none in the last 12 months and its latest release was in January 2022, indicating a long registry release gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The single workflow was fully analyzed with no untrusted checkout or script-injection trigger, but it enables high-confidence insecure commands and all 3 of 3 action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
seld/cli-prompt Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.