The package has clear usage documentation, release notes for 3.0.0, repository tests, and organization backing. Its small dependency surface and read-only workflow permissions are reassuring, though security scanning is absent.
60%
Total Score
75
100
90
50
The latest release was published about 22 months ago, and there were no releases in the last 12 months. This indicates slowing maintenance, although the package has a multi-year history and 10 releases.
The repository recorded no commits and no active maintainers in the last 3 months, supporting the broader evidence of reduced maintenance activity.
The repository has no published security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself indicate abandonment.
The single workflow uses read-only permissions and has no untrusted checkout or injection findings. However, both analyzed action references are unpinned, leaving a modest reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pear/archive_tar Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.