The package is documented, tested, licensed, and has a recent release with a matching source repository. Maintenance activity is currently quiet, and all 15 workflow action references are unpinned, leaving meaningful upkeep and build-integrity concerns.
68%
Total Score
50
100
88
67
The package has existed for over 10 years and released once in the last 12 months, with the latest release about 7 months before collection. That shows continuity but a slower current cadence.
The repository recorded zero commits and zero active maintainers over the last 3 months. The same-day release is some compensating evidence, but ongoing maintenance capacity remains uncertain.
Composer and Make are used for project tooling, but no security-scanning tools were detected. For a small library this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All five workflows were analyzed without high- or medium-severity findings, and no untrusted checkout or script-injection paths were found. However, all 15 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.