No commits or active maintainers were recorded in the last three months, and the release documentation calls this an unsupported fork of an end-of-life project. The package is licensed and has a substantial README, changelog, and security policy, but workflow references are all unpinned.
35%
Total Score
0
71
83
The package includes a substantial README, changelog, and release notes, but those notes explicitly identify this as an unsupported fork and the README says Pico development stopped long ago and advises against new websites. The documentation is transparent, yet it confirms substantial abandonment risk.
The repository recorded 0 commits and 0 active maintainers during the last three months. That indicates no current maintenance capacity for a package already described as unsupported.
All 37 releases occurred within a single day, with a median interval of 0 days, which suggests a concentrated fork publication burst rather than an established ongoing release cadence.
The repository uses Make and Composer, but has no security scanning tools. This is a modest transparency and maintenance gap, though it is partly offset by the repository having a security policy.
All 13 analyzed action references are unpinned, leaving workflow dependencies exposed to upstream changes. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.11.3 | — | — |
symfony/yaml Version ^5.4.35 | — | — |
erusev/parsedown Version 1.7.4 | — | — |
erusev/parsedown-extra Version 0.8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.