Release activity is sparse, and the small repository has limited evidence of ongoing development beyond two recent commits. The organization backing, security policy, and release notes provide useful context but do not offset the adoption risk.
18%
Total Score
83
100
50
100
Packagist marks the entire package as abandoned, with no replacement package specified. This is a direct warning against taking a new dependency on it.
The linked repository is archived, which strongly indicates that normal maintenance has ended even though it was pushed on July 22, 2026.
The package has had no releases in the last 12 months and only five releases since April 2023. That quiet cadence increases abandonment risk, especially alongside the package-level deprecation.
Only two commits were recorded in the last three months, despite two active contributors. This shows some recent activity but not a strong maintenance pace.
The single workflow is fully analyzed and has no reported audit findings or untrusted checkout or script-injection sinks. However, its only action reference is unpinned, which is a minor supply-chain hygiene gap; the pull_request_target trigger is not risky by itself here.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.