Documentation and licensing are in good shape, with a focused dependency set and no install-time scripts. No commits landed in the measured three-month window, while all 8 CI action references are unpinned and a medium-confidence bot-condition warning remains.
68%
Total Score
75
100
75
The repository recorded zero commits and zero active maintainers in the measured three-month window, a meaningful sign of currently thin maintenance activity despite the recent package release.
No repository security policy was found, leaving vulnerability-reporting guidance unclear; this is a minor transparency gap rather than evidence of abandonment.
The workflow audit completed fully and shows read-only permissions with no untrusted checkout or script-injection findings. However, all 8 action references are unpinned, and it reports a medium-confidence bot-condition finding, so CI hygiene warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.0@dev || ^4.0@dev | — | — |
nepada/email-address Version ^2.3@dev || ^3.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.