The module has a clear license, tests, release notes, organizational backing, and a recent repository push. Registry releases have stopped for about 21 months, three-month commit activity is absent, and all 15 workflow actions are unpinned; pin this version if adopting it.
67%
Total Score
75
100
88
67
The package has 18 releases over roughly 10 years, but none in the last 12 months and the latest registry release was about 21 months ago. This indicates a meaningful slowdown, though the repository was pushed more recently.
There were no commits and no active maintainers in the last three months. The recent repository push shown by repository_archived partly offsets this, but the current commit silence still lowers maintenance confidence.
The repository uses Composer for builds, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented. The package's tests and organizational backing provide some context but do not replace a policy.
All three workflows were analyzed successfully and no dangerous triggers, untrusted checkouts, script injections, or audit findings were reported. However, all 15 action references are unpinned, which leaves workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.