The project has tests, release notes, a clear license, and organizational ownership. Its workflows use five unpinned actions and the repository has no security policy, so maintenance hygiene deserves attention.
68%
Total Score
67
100
100
75
All recent commit activity comes from one contributor, leaving maintenance dependent on a single active contributor; organizational ownership provides some handoff capacity but does not remove the concentration.
Only one commit was recorded in the last three months, with one active maintainer, indicating limited recent maintenance capacity despite the recent repository push.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all five action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
league/flysystem Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.