The repository includes tests, release notes, a matching README, and a clear MIT license. Its workflows use unpinned actions and contain a medium-confidence template-injection warning, so maintenance and build hygiene deserve attention.
58%
Total Score
67
100
88
63
The package has had no release in about four years and nine months, with zero releases in the last 12 months. Its four-release history shows a real abandonment concern despite the package's small testing-focused scope.
There were no commits and no active maintainers in the last three months, consistent with the release history showing no releases since January 2022. This materially raises abandonment risk.
Composer install and update lifecycle scripts are present, so installation can execute package-defined commands. This is a supply-chain hygiene concern, although the signal does not show that the scripts are harmful.
No repository security policy is present. This is a minor transparency gap for a small package and does not outweigh its otherwise clear source and licensing information.
All four workflows were analyzed with no untrusted checkouts or script injections, but all 16 action references are unpinned and the audit found a medium-confidence template-injection pattern in CI. These are build-hygiene concerns rather than a severe risk on their own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.