The repository is active, documented, tested, and backed by an organization. However, this is a one-day-old pre-1.0 project and every workflow action is unpinned.
70%
Total Score
100
100
88
75
The package is only 1 day old with 3 releases, so there is little evidence yet of long-term maintenance or release stability, despite the recent activity.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
Version v0.4.0 is not a stable major release, so the public API may still change as the very new project matures.
All 3 workflows were analyzed, use read-only permissions, and have no detected dangerous findings. However, all 16 action references are unpinned, leaving workflow execution exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.3.0 | — | — |
illuminate/container Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.