The package has clear documentation, an MIT license, release notes, and a repository that matches its name. Its registry releases stopped over a year ago and recent repository activity is absent, while all five workflow actions are unpinned.
48%
Total Score
75
93
67
The package has 173 releases, but none in the last 12 months and its latest release was over a year ago. That prolonged registry inactivity is a meaningful abandonment concern despite the substantial release count.
The repository recorded no commits and no active maintainers in the last three months. This reinforces the evidence that maintenance has stopped rather than merely slowed.
The linked repository has no security policy. This reduces transparency for reporting vulnerabilities, although it does not by itself show that the package is unsafe.
The audit covered both workflows with no dangerous triggers or findings, but all 5 of 5 action references are unpinned. That leaves build inputs exposed to upstream changes and is a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2.2 | — | — |
symfony/yaml Version ^6.0|^7.0 | — | — |
shalvah/clara Version ^3.1.0 | — | — |
fakerphp/faker Version ^1.23.1 | — | — |
erusev/parsedown Version 1.7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.