The package includes a README, tests, a small dependency surface, and read-only workflow permissions. Its license declaration and repository security tooling improve transparency, but there is no recent release activity and the project has little visible adoption.
12%
Total Score
57
50
Packagist marks the entire package as abandoned, with no replacement given; this is a direct warning against taking a new dependency on it.
Only two releases were published, both in June 2022, with none in the last 12 months; this strongly indicates abandonment rather than an actively maintained release line.
The linked repository is archived, which indicates the project is no longer an active maintenance target despite a recorded push on May 3, 2026.
Both workflows use read-only permissions and the audit found no dangerous triggers, sinks, or high-confidence findings. All four action references are unpinned, a minor reproducibility weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.