The source includes tests, a changelog, MIT licensing, and a matching repository, while Dependabot and Composer provide some project structure. Those positives do not offset the release being withdrawn and the absence of recent commit activity.
18%
Total Score
50
71
67
Packagist marks the entire package as abandoned and lists nails/module-api as its replacement, making this release unsuitable for a new dependency despite the linked repository remaining available.
This package has only one release, published about 12 years and 3 months ago, with no releases in the last 12 months; that is strong evidence of abandonment.
The repository recorded zero commits and zero active maintainers in the last 3 months, so there is no observed recent maintenance to offset the stale registry history.
No repository security policy was found, leaving a transparency gap for reporting vulnerabilities, though this is secondary to the package's abandonment evidence.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nailsapp/common Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.