Workflow hygiene is imperfect, with unpinned actions and inherited secrets increasing maintenance risk. The package is otherwise clearly structured, licensed, tested in the repository, and backed by security tooling.
58%
Total Score
67
100
89
100
Six releases were published within the last 12 months, but all occurred between December 1 and December 19, 2025, showing an initially active burst rather than sustained release activity.
There were no commits and no active maintainers in the last three months, a meaningful maintenance concern for a package intended to be depended on.
There are no new or closed issues in the last month and two open pull requests, suggesting limited recent community activity but not clear abandonment by itself.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly reduces maturity evidence but does not determine the verdict.
All eight workflows were analyzed, but all 17 action references are unpinned, one high-confidence finding uses a floating container image tag, and several workflows inherit secrets. No untrusted checkout or script-injection sink was found, so this is a hygiene and maintenance caution rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpolar/storage Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.