The repository has tests and the release is stable, with organization backing and no install-time scripts. Workflow actions are all unpinned and one uses an archived action; the repository also lacks a security policy.
58%
Total Score
67
92
67
The package has 23 releases over more than 10 years, but it has had no release in nearly three years. That materially raises abandonment risk despite its historically established cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and suggesting maintenance has stopped or sharply slowed.
There were no new or closed issues and no merged pull requests in the last month, while four issues remain open. This provides additional evidence of limited current maintenance.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it does not by itself indicate the package is unsafe.
All 9 analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action. The workflows have no untrusted checkout or script-injection findings, which limits the risk to workflow hygiene rather than a severe exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netcommons/tags Version @dev | — | — |
netcommons/files Version @dev | — | — |
cakedc/migrations Version ~2.2 | — | — |
netcommons/net-commons Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.