The project includes repository tests, release notes for this version, and Psalm checks. Its unpinned workflow actions and lack of a security policy add maintenance and supply-chain hygiene concerns.
58%
Total Score
86
50
The latest release was over three years ago, with no releases in the last 12 months; this is a meaningful sign of slowing maintenance despite three releases over the package's lifetime.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap for a maintained library.
Version v0.2.0 is not a stable major release, which signals an immature API and increases adoption risk, although it is not marked as a prerelease.
Both workflows were analyzed successfully with no high-confidence dangerous findings, and no untrusted checkout or script-injection paths were found. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vimeo/psalm Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.