This release appears healthy and suitable to depend on: it has a stable release profile with 8 releases in the last 12 months, active repository maintenance with 25 commits and 8 active maintainers in the last 3 months, balanced contributor participation, non-archived and organization-backed source ownership, repository tests, security scanning, and a security policy. The main residual concerns are low repository popularity and GitHub Actions permission hygiene, including several workflows without explicit top-level permissions and one workflow with top-level write permissions; these warrant review but do not outweigh the strong maintenance and transparency evidence.
88%
Total Score
100
100
100
80
Two of ten workflows use pull_request_target, which requires careful review because it can run with elevated repository context. However, no untrusted checkouts or script-injection patterns were detected, limiting the concern to workflow design risk.
Seven workflows lack explicit top-level permissions, and one workflow declares top-level write permissions. Although two workflows use read-only permissions and no exploit is shown, this is a genuine least-privilege hygiene gap in the build pipeline.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^2.11 || ^3.0 | — | — |
pimcore/pimcore Version ^2026.1 | — | — |
opensearch-project/opensearch-php Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.