The package has a clear license, tests, README, release notes, and modest dependencies. Its missing security policy and two unpinned workflow actions leave build hygiene weaker than ideal.
62%
Total Score
50
100
94
75
This is the only release, published about eight months ago, so there is no demonstrated release cadence yet. The package is still relatively young, which limits how strongly this indicates abandonment.
There were no commits and no active maintainers in the last three months, following the sole release. For a package only about eight months old this is a meaningful maintenance concern, though not conclusive abandonment.
No repository security policy was found, reducing transparency about how vulnerability reports are handled.
The single workflow was fully analyzed with no dangerous triggers or audit findings, and it does not grant top-level write permissions. However, both of its two action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.