Clear documentation, release notes, repository tests, and organization backing improve adoption confidence. The build uses security tooling, but maintenance and workflow pinning deserve attention before taking updates.
60%
Total Score
75
83
50
The package has made no release in over a year, despite a previously regular median interval of about five months. This suggests slowing maintenance and lowers confidence in ongoing support.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release provides some evidence of maintenance, but current activity is still absent.
No security policy was found, leaving vulnerability reporting and response expectations undocumented. Repository security scanning partly compensates by showing active security tooling, so this is a transparency gap rather than a severe risk.
All 20 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image. Read-only permissions across all workflows reduce exposure, but mutable build inputs remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr-discovery/discovery Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.