The repository is organized, tested, licensed, and maintained under an organization-owned project. Composer dependencies are modest, but security scanning is absent and all nine workflow actions are unpinned.
68%
Total Score
75
100
88
75
The package has eight releases over about five years, but none in the last 12 months; the latest release was about 20 months ago. This is a meaningful sign of slowing maintenance, though not abandonment by itself.
There were zero commits and zero active maintainers in the last three months. Combined with no registry releases in the last year, this raises maintenance and abandonment risk.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene weakness rather than evidence that the package is unsafe.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations, although it does not by itself show poor maintenance.
All workflows were analyzed with no untrusted checkouts, injection findings, or high-severity issues. However, all nine action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0||^2.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.