The MIT license, clear README, changelog, and small runtime dependency keep installation and use straightforward. Its workflows use unpinned actions, while the repository has no security scanning or published security policy. The repository is not archived, but maintenance appears to have stopped.
55%
Total Score
50
100
83
50
The package has only 3 releases, with 0 releases in the last 12 months; its latest release was published on May 19, 2023. This long pause materially raises abandonment risk, though the stable 1.1.0 version is not inherently immature.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of recent releases. The repository is still available and not archived, which limits this to a maintenance concern rather than a severe fitness risk.
The project uses Composer and Box for build and packaging, which supports reproducible project structure. No repository security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no SECURITY.md or other published security policy. The README provides a security email, which offers a contact path but is less explicit and structured than a maintained policy.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and one scopes permissions at job level. However, all 8 action references are unpinned, weakening build provenance and making workflow dependencies easier to change unexpectedly.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.