All ten workflow actions are unpinned, and the repository has no security policy. The package still has a long release history and a current GitHub release.
65%
Total Score
67
100
100
75
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance warning even though the registry shows recent releases.
No issues or pull requests were opened or merged in the last month, adding to the uncertainty about current project responsiveness.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
All five workflows were analyzed successfully with no high-confidence audit findings or untrusted-trigger sinks, but all 10 action references are unpinned, creating a workflow reproducibility and update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gin0115/dice Version 4.1.* | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
pinkcrab/hook-loader Version ^1.1 | — | — |
pinkcrab/function-constructors Version 0.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.