The repository is small but includes tests, a README, and an exact package match; its MIT licensing and organization ownership add useful transparency. Unpinned workflow actions and no security policy leave maintenance hygiene weaker.
52%
Total Score
75
90
50
Only two releases were published, both within about two days, and none appeared during the following 2 years and 7 months. This makes ongoing maintenance uncertain for a development tool.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with the long release gap. The repository is not archived, but recent maintenance is not evident.
The linked repository has no security policy. This is a transparency and response-process gap, although the package is a testing tool rather than a primary runtime service.
The single workflow was fully analyzed with no audit findings or untrusted checkouts, but all 4 action references are unpinned. The absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
olifanton/ton Version ^1.1.0 | — | — |
symfony/console Version ^6.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
danog/class-finder Version ^0.4.8 | — | — |
nette/php-generator Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.