The repository is not archived, and the package includes a clear README, repository tests, release notes, and explicit licensing. Its small audience, missing security policy, unpinned workflow actions, and stalled recent activity add maintenance and hygiene concerns.
61%
Total Score
50
86
67
The package has 10 releases, but none in the last 12 months; its latest release was about 17 months ago. The earlier roughly one-day median interval shows an initially active project but does not offset the current pause.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is a meaningful maintenance warning, although the repository was pushed more recently according to the separate archive signal.
The repository has 0 stars, 0 forks, and 1 watcher, so there is little visible community adoption or independent support. Popularity is supporting evidence rather than decisive proof, but it provides no compensating maturity signal here.
No security policy was found in the repository. For a library that implements digital signing and verification, this weakens vulnerability-reporting transparency.
All 3 workflows were analyzed successfully with no injection sinks or audit findings, but all 3 action references are unpinned. The absence of top-level permissions blocks is acceptable on its own, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
petrknap/binary Version ^4.0|^5.0 | — | — |
petrknap/shorts Version ^3.0 | — | — |
petrknap/optional Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.