The package includes tests, a changelog, a license, and a matching repository. Organization backing helps, but inactive recent commits and workflow hygiene warrant caution when updating.
62%
Total Score
75
79
50
The sole workflow was fully analyzed with no untrusted checkout or script-injection path, but its container image is unpinned with high-confidence severity and all 49 action references are unpinned. This weakens build reproducibility and supply-chain hygiene.
The package has 53 releases over about five years, but none in the last 12 months; its latest release was about 16 months ago. This indicates a meaningful slowdown despite a previously regular median interval of about 29 days.
No commits or active maintainers were recorded in the last three months, reinforcing the release-history slowdown and raising maintenance risk.
The repository uses Composer for builds, but no security-scanning tools were detected. This is a modest transparency and assurance gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a package that contains application and API code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
miaoxing/app Version ^0.10.11 | — | — |
miaoxing/admin Version ^0.17.3 | — | — |
miaoxing/link-to Version ^0.1.64 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.