The package includes a clear license, tests, a README, and release notes for this version. Workflow references are unpinned and the repository has no security policy or scanning, adding maintenance and supply-chain hygiene concerns.
64%
Total Score
50
92
50
Only two releases exist, with no release in the last 12 months; the latest registry release was about 1 year 11 months ago. Recent repository commits partly offset the stale registry cadence, but do not remove the adoption risk.
The repository had one contributor responsible for all two commits in the last three months, leaving maintenance concentrated in a single person. The active commits are positive, but there is no demonstrated contributor redundancy.
No repository security policy or security scanning tool was detected, reducing transparency around vulnerability reporting and automated checks. The package's tests and active recent commits provide some compensating project evidence.
All 18 analyzed action references are unpinned and one workflow grants top-level write permissions, which weakens build reproducibility and token minimization. No untrusted checkout, script injection, dangerous trigger, or auditor finding was reported, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2 | — | — |
psr/http-message Version ^2 | — | — |
mulertech/char-manipulation Version ^1 | — | — |
mulertech/array-manipulation Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.