The release is clearly documented, licensed, and backed by repository tests. Its small dependency surface and clean workflow audit do not offset the lack of a maintained path forward.
18%
Total Score
75
100
50
83
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The package has had only two releases, both in October 2020, with no releases in nearly six years. This strongly indicates abandonment rather than an actively maintained stable release.
The source repository is archived, and its last push was nearly four years ago. An archived project has no active maintenance path for future fixes or compatibility changes.
The repository recorded no commits and no active maintainers during the measured three-month period. This supports the abandonment concern shown by the archived and deprecated status.
The single workflow was fully analyzed with no reported audit findings or dangerous trigger/sink combination. However, all six action references are unpinned, which is a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.