The package has a clear README, matching source tree, MIT licensing, and automated security scanning. Its small scope and three runtime dependencies keep adoption straightforward, but workflow hygiene is uneven.
12%
Total Score
100
69
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption and maintenance risk even though the assessed release is stable.
The linked repository is archived, despite being pushed on August 13, 2025. An archived source repository is a severe indicator that future maintenance is unlikely.
The package has 16 releases over about four years, but none in the last 12 months and its latest release was August 2, 2025. This supports a substantial maintenance concern alongside the archived repository.
All 23 analyzed action references are unpinned, and high-confidence bot-condition and template-injection findings were reported. No untrusted checkout or script-injection sink was found, so this is a workflow hygiene concern rather than the primary adoption risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.2 | — | — |
laminas/laminas-mvc Version ^3.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.