The project includes tests, release notes, a clear license, and a security policy. Its small release history, no commits in the last three months, and entirely unpinned workflow actions reduce confidence in ongoing maintenance and build reproducibility.
65%
Total Score
50
100
88
100
The package has five releases over about six years, with one release in the last 12 months and a median interval of about 464 days. This indicates slow maintenance rather than clear abandonment, but limits confidence in frequent fixes.
There were no commits and no active maintainers in the last three months. Although a release occurred recently, the lack of current repository activity is a meaningful maintenance concern.
The repository uses Make and Composer, but no security scanning tools were detected. Build tooling is present, while the missing automated security checks modestly reduce assurance.
The single workflow was fully analyzed with no injection, untrusted-checkout, or severity-rated findings. However, all four action references are unpinned, leaving build inputs less reproducible and increasing dependence on mutable action versions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.