The small package has clear licensing, repository tests, and basic static security tooling. Recent work is concentrated in one contributor, and all 15 workflow actions are unpinned; the repository also does not clearly identify the package. Pin this version if adopting it.
68%
Total Score
83
88
50
All 6 recent commits came from one contributor, leaving maintenance dependent on a single active person even though the repository is organization-owned.
The repository name does not match the package name, and no README package mention was available, so the linkage is less transparent; a name mismatch alone can also occur for a sub-package or monorepo.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities.
Version 0.4.3 is not a stable major release, so its pre-1.0 status implies some API-change risk, but it is not marked as a prerelease.
The workflow audit found no dangerous triggers, sinks, or high-confidence findings, and one workflow uses read-only permissions. However, all 15 analyzed action references are unpinned, leaving avoidable supply-chain reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0.0 | — | — |
psr/simple-cache Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.