The package is licensed, documented, tested, and backed by an organization. Its workflows use five unpinned actions and the repository lacks a security policy, so ongoing upkeep deserves attention.
63%
Total Score
75
92
50
Only two releases exist, with the latest published over three years ago and no releases in the last 12 months. This indicates a meaningful maintenance concern despite the stable 1.1.0 version.
The repository recorded no commits and no active maintainers in the last three months. The repository was pushed more recently than the last release, but current development activity is still absent.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is not evidence that the package is unsafe.
All five analyzed action references are unpinned, which weakens build reproducibility. The audit was complete and found no dangerous triggers, untrusted checkouts, script injection, or other reported findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 | ^2.0 | ^3.0 | — | — |
ramsey/uuid Version ^4.1 | — | — |
oat-sa/lib-health-check Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.