The package includes a clear license, README, tests, and a stable major release, giving consumers useful documentation and structure. Its small project footprint and missing security policy provide limited assurance for long-term maintenance.
62%
Total Score
50
93
67
The package has six releases since January 2023, but none in the last 12 months; the latest release is now about one year old, indicating a meaningful slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, which is direct evidence of currently stalled development.
Six pull requests were opened in the last month but none were merged, while one issue was opened and none were closed; this suggests unresolved maintenance activity rather than effective project movement.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, but it is partly offset by the package's small scope and visible tests.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 9 action references are unpinned, leaving build dependencies exposed to moving upstream versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.