The MIT license, clear README, and changelog make its contents easy to inspect. A missing security policy, no security scanning, and unpinned workflow actions leave less evidence for ongoing care.
42%
Total Score
50
86
75
All 18 releases were published within one day, with no later release activity across roughly nine months. That pattern suggests a one-time repackaging or migration rather than sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, despite being assessed about nine months after its last push. For a compatibility plugin, that is meaningful abandonment risk.
The repository uses Make and Composer, showing a defined build path, but no security-scanning tool was detected. This weakens ongoing maintenance transparency without proving the release is unsafe.
No security policy was found in the repository. That leaves contributors and users without a documented vulnerability-reporting process.
All four analyzed action references are unpinned, which weakens workflow reproducibility. The reported cache-poisoning finding has low confidence and is hygiene rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phrozenbyte/pico Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.