It has no security policy, and its workflows use nine unpinned actions including an archived action. The organization-backed repository has tests, a README, and a release record, but those positives do not offset the lack of recent maintenance.
56%
Total Score
75
100
86
50
The latest release was in October 2023, with no releases in the last 12 months; nearly three years without a release lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The project uses Composer, but no security scanning tools were detected, leaving a security-maintenance gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
All nine analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action; no untrusted checkout or script-injection paths were found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakedc/migrations Version ~2.2 | — | — |
netcommons/net-commons Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.