The package has repository tests, release notes for this version, and no install-time scripts. Recent work is concentrated in one contributor, and all 11 workflow actions are unpinned, so maintenance and build reproducibility deserve attention.
78%
Total Score
67
100
67
One contributor made all recent commits, leaving maintenance dependent on a single active contributor; organization backing helps provide continuity but does not remove the concentration concern.
Only 1 commit was recorded in the last 3 months, indicating limited recent activity compared with the package's otherwise regular release history.
The repository has no published security policy, which is a transparency gap for reporting and handling vulnerabilities.
The workflow audit completed successfully with no dangerous triggers, untrusted checkouts, or findings, but all 11 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psalm/psalm-plugin-api Version ^0.1|^0.2|^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.