The repository still includes tests, release notes, and a matching project, while its MIT licensing is clear. Workflow references are all unpinned, adding avoidable maintenance risk.
57%
Total Score
50
92
50
The package has had no release in more than four years, with zero releases in the last 12 months. Its five-release history shows a real project, but the long pause raises abandonment concerns.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged release pause and indicating limited current maintenance capacity.
No repository security policy was found, leaving vulnerability-reporting expectations less transparent. This is a modest governance gap rather than evidence that the package is unsafe.
All 26 analyzed action references are unpinned, so workflow dependencies can change without a repository commit. There were no untrusted checkouts, script injections, high-severity findings, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
fig/http-message-util Version ^1.1 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.