The stable 3.0.3 release has a clear README, MIT license, release notes, and repository tests. Its maintenance and security hygiene do not offset the package withdrawal and inactive source, so choose an actively maintained replacement.
10%
Total Score
50
100
75
100
Packagist marks the entire package as abandoned, with no replacement specified. This directly indicates that new projects should not take a dependency on it.
The linked source repository is archived, despite a last push in November 2025. An archived repository is a strong indication that fixes and future maintenance should not be expected.
The repository had zero commits and zero active maintainers during the last three months, reinforcing the abandonment signal rather than showing ongoing maintenance.
All 18 analyzed action references are unpinned, which weakens build reproducibility, and the audit found a high-confidence template-injection issue. No untrusted checkout or script-injection trigger was reported, so this is a hygiene concern rather than an independent severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1.2 || ^2.0.2 | — | — |
mezzio/mezzio-laminasviewrenderer Version ^2.19.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.