The MIT license, repository tests, and release notes provide useful baseline transparency. Security coverage is absent and all eight workflow actions are unpinned, adding maintenance and build-trust concerns.
55%
Total Score
50
93
75
The latest release was published nearly six years ago, with no releases in the last 12 months. Its five-release history and roughly monthly median interval show an established package, but current maintenance is uncertain.
The repository recorded zero commits and zero active maintainers in the last three months. A push in May 2026 shows the repository is not wholly abandoned, but it does not offset the lack of recent development activity.
No security policy was found in the repository. This weakens vulnerability-reporting transparency, though it is a hygiene gap rather than evidence that the package is unsafe.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or high-severity findings, and no top-level write permissions. However, all eight action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^0.8.4 | — | — |
react/promise Version ^2.5 | — | — |
laravie/stream Version ^1.3 | — | — |
league/climate Version ^3.5 | — | — |
katsana/minions Version ^1.6 || ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.