The source repository is active enough to remain available, matches the package, and the release is licensed and stable. Its small audience, absent security policy, stale release cadence, and workflow pinning gaps warrant checking changes before adoption.
61%
Total Score
75
88
75
The package has 27 releases since May 2020, but none in the last 12 months; the latest registry release was about 15 months ago. This is a meaningful maintenance concern, although the repository was pushed more recently.
There were no commits and no active maintainers in the last three months. The recent repository push is compensating evidence, but the short-term commit record still indicates limited visible development activity.
The repository uses Composer, but no security scanning tools were detected. This is a maintenance and transparency gap, not evidence that the package is unsafe.
The repository has no security policy. Consumers therefore have no documented security-reporting process, which modestly lowers project transparency.
Both workflows were analyzed successfully with no untrusted checkout or script-injection findings, but all 7 action references are unpinned and two high-confidence archived-uses findings were reported. These are workflow hygiene and supply-chain maintenance concerns, not a severe risk by themselves.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.