The repository has 199 commits in three months, tests, release notes, security policy, and active organization backing. The single-contributor base, first pre-1.0 release, and workflow audit findings leave meaningful adoption risk.
62%
Total Score
75
50
79
67
All workflows were analyzed, but all 48 action references are unpinned; high-confidence template injection with an untrusted checkout path is a serious workflow hygiene concern, while high-confidence ad hoc package installs add smaller risk. The workflow audit also reports a workflow_run trigger and an untrusted checkout, although the reported paths do not establish that every issue occurs together.
The package declares 26 runtime dependencies, including database, telemetry, HTTP, and messaging components; that broad dependency surface increases maintenance and compatibility exposure.
This is the only release, published 64 days ago, so there is not yet enough release history to demonstrate sustained maintenance.
All 199 recent commits came from one contributor, creating a significant continuity and handoff risk despite the repository being organization-owned.
The repository opened 12 pull requests in the last month and has 20 open pull requests, showing active development, though none were merged in that period.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
brick/math Version ^0.12 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/uid Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.