It has tests, a clear MIT license, and regular releases over its first year. The single-user project has gone three months without commits, while its release workflow needs stronger pinning.
64%
Total Score
50
100
50
One registry account has publishing access, and the project is backed by a personal repository rather than an organization; this leaves a thin apparent maintainer base.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release history.
The repository has no published security policy, reducing transparency for vulnerability reporting and maintenance expectations.
All 10 analyzed action references are unpinned, weakening build reproducibility. The reported cache-poisoning issue has low confidence, so it is treated as hygiene rather than a severe risk; the audit itself is complete.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/sync Version ^2.3 | — | — |
amphp/cache Version ^2.0 | — | — |
ramsey/uuid Version ^4.9 | — | — |
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.