The repository includes integration tests, release notes, dependency scanning, and a clear MIT license. Automation is only partly hardened because 11 of 17 actions are unpinned and one archived action remains; the small project also has little visible community activity.
61%
Total Score
67
100
94
83
The package has had only 3 releases, with none in the last 12 months; the latest release was in May 2023. This is meaningful evidence of slowing maintenance, though the repository remains active enough to avoid treating the package as abandoned outright.
There were 0 commits and 0 active maintainers in the last 3 months. This indicates limited recent development capacity, even though the repository is not archived.
There were no new or closed issues or pull requests in the last month, with 8 open pull requests and 1 open issue. This suggests low current project activity and unresolved maintenance work.
The repository has no security policy. This is a transparency gap, but it is less serious because the project does use Dependabot and Psalm.
All 6 workflows were analyzed and no untrusted checkout or script-injection paths were found, but 11 of 17 action references are unpinned and a high-confidence medium-severity archived action was found in release.yaml. The absence of top-level permissions blocks is acceptable on its own and no workflow has top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.