The package has a clear README, matching source repository, explicit licensing, and no install-time scripts. Its single-maintainer project has shown no commits or releases for about four years, while security tooling and a security policy are absent.
58%
Total Score
50
88
83
Only one registry maintainer is listed, leaving limited publishing redundancy. This is partly consistent with the repository being owned by an individual, but still increases continuity risk.
Only three releases have appeared since May 2020, with no release in roughly four years and none in the last 12 months. This is a meaningful maintenance concern for a package used in deployment workflows.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. This indicates materially reduced maintenance capacity.
There has been no issue or pull-request activity in the last month, with one issue and one pull request still open. This provides no evidence of current project attention.
Composer is used for the build, but no security scanning tools were detected. For a plugin handling encrypted secrets, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.