Documentation, tests, release notes, and licensing are all in good shape. Workflow references are entirely unpinned, and the repository lacks a security policy, increasing maintenance and build-hygiene concerns.
61%
Total Score
75
100
88
75
The package has made no registry release in nearly five years, which raises abandonment and compatibility concerns even though the repository was pushed recently.
There were no commits and no active maintainers in the last three months, weakening the evidence of ongoing maintenance despite the recent push timestamp.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest repository-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
All 14 analyzed action references are unpinned, and the audit found high-confidence template-injection patterns; the latter is hygiene risk here because no untrusted trigger or checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micropackage/filesystem Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.