Unpinned workflow actions and a low-confidence cache warning add supply-chain hygiene concerns. The package remains documented and supported by an organization with repository tests and release notes.
63%
Total Score
67
100
88
100
The package has 17 releases over nearly six years, but none in the last 12 months, which is a meaningful maintenance concern for a dependency.
No commits or active maintainers were recorded in the last three months, indicating a recent maintenance lull despite the repository being unarchived.
Four issues and three pull requests remain open, while none were opened, closed, or merged in the last month; this suggests limited current activity but not abandonment alone.
The project uses Make and Composer, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
All six analyzed action references are unpinned, and the auditor reported a low-confidence high-severity cache-poisoning pattern in the release workflow; there are no untrusted checkouts or script injections, so this is a hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.