The source is still maintained and this release includes notes for recent schema updates. The repository-to-package naming mismatch and unpinned workflow dependencies add smaller trust and maintenance concerns.
22%
Total Score
50
79
100
Packagist marks the entire package as abandoned, with no replacement specified. This outweighs the repository's recent activity and makes depending on this release a serious liability.
There were no commits and no active maintainers in the preceding 3 months. The very recent push and release history provide some compensation, but this still indicates limited recent development activity.
The repository name does not match the package name and its README does not mention the package. Although this can occur with organizational repositories, the lack of an explicit package reference weakens source-to-artifact transparency.
The single workflow was fully analyzed and has no untrusted checkouts or script injection, but both action references are unpinned and it installs a package outside a lockfile. The low-confidence audit finding is hygiene risk rather than a severe workflow threat.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.