Recent maintenance has stalled, with no commits in the last three months and only one release in the last 12 months. The workflow also leaves all 12 actions unpinned and has a high-confidence credential-persistence finding, while tests, release notes, and licensing provide useful support.
62%
Total Score
50
88
75
The only workflow was fully analyzed, but all 12 action references are unpinned and the high-confidence artipacked finding reports that checkout credentials are not disabled with persist-credentials: false. These create avoidable workflow supply-chain exposure.
The package has existed for about 780 days with five releases, but only one release in the last 12 months; that indicates a slower maintenance pace without proving abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has paused recently.
The project uses Make and Composer, showing established build tooling, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
apache/avro Version dev-main#c499eefb48aa2db906c7bca14a047223806f36db | — | — |
beberlei/assert Version ^2.9.9|~3.0 | — | — |
guzzlehttp/promises Version ^1.4.0|^2.0.0 | — | — |
widmogrod/php-functional Version ^6.0|^7.0 | — | — |
mattiabasone/confluent-schema-registry-api Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.