The source is still being updated, with an MIT license, a substantial README, and security scanning in place. Its maintenance depends on one contributor, while the workflow references are unpinned and no security policy is published.
38%
Total Score
75
75
50
Packagist marks the entire package as abandoned and names lineage-ota as its replacement. This is a major adoption concern even though the repository remains active.
One contributor made all 12 recent commits, leaving no demonstrated backup for ongoing maintenance. The individually maintained project has a concentrated bus factor.
The linked repository name does not match the package name and its README does not mention this package. That mismatch makes the package-to-source relationship less transparent, despite the repository appearing related to the same OTA project.
The repository has no published security policy, so users have no documented channel or process for reporting vulnerabilities. This is a transparency gap for a server package.
All five analyzed action references are unpinned, which weakens build reproducibility and lets referenced action code change without a reviewed version. The audit found no dangerous triggers, sinks, or high-confidence workflow findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 3.* | — | — |
mikecao/flight Version 2.* | — | — |
julianxhokaxhiu/dotnotation Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.