A small release history and no commits in the last three months leave maintenance capacity uncertain. The README, release notes, license, repository tests, and security policy provide useful support, but all eight workflow actions are unpinned.
68%
Total Score
50
100
86
100
The package is about 839 days old with six releases, two in the last 12 months, and a median interval of about 117 days. This shows ongoing releases but a modest cadence.
The repository recorded zero commits and zero active maintainers in the last three months. The recent v0.1.5 release is positive, but the current inactivity weakens evidence of ongoing maintenance.
Version v0.1.5 is not a prerelease, but the package remains below major version 1, so compatibility expectations are less mature than for a stable-major release.
All eight analyzed action uses are unpinned, and the audit found one high-confidence template-injection issue in update-changelog.yml. No untrusted checkouts, script injections, dangerous triggers, or top-level write permissions were observed, limiting this to a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.