Recent repository activity has stopped, and only two releases appeared in the last year. Tests, a changelog, organization backing, and a non-deprecated stable release provide useful support, but all three workflow actions are unpinned.
62%
Total Score
50
100
89
67
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is the clearest maintenance concern and raises the risk that fixes may not arrive promptly.
The package has 45 releases over 970 days, but only 2 releases in the last 12 months, indicating a materially slower release pace than its historical cadence.
The repository has 1 star, 0 forks, and 11 watchers. Low popularity is supporting context rather than a health verdict, especially with organization backing and project artifacts present.
The repository has no security policy. This limits transparency about vulnerability reporting, though it is partly offset by Dependabot scanning.
The single workflow was fully analyzed with no reported audit findings or untrusted inputs, but all 3 action references are unpinned, leaving the workflow exposed to moving action contents.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
monolog/monolog Version ^1.27 | — | — |
webmozart/assert Version ^1.7 || ^1.8 || ^1.9 | — | — |
guzzlehttp/guzzle Version ~7 | — | — |
league/oauth2-client Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.