It has a clear MIT license, a substantial README, repository tests, and organization backing. All three workflow actions are unpinned, and the repository has no security policy or security scanning.
52%
Total Score
50
70
50
The package has 32 releases, but none in the last 12 months; its latest release was on December 22, 2023, indicating prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history and increasing abandonment risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; the absence of security scanning adds some hygiene concern.
The assessed release is 3.4.4, while the collected registry metadata reports latest_version as 2.0.3. This inconsistency reduces confidence in release metadata and version maintenance.
All 3 of 3 analyzed action references are unpinned, which weakens reproducibility. The audit otherwise found no injection, untrusted checkout, excessive-write-permission, or high-severity findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^4.3.0 | — | — |
ruflin/elastica Version ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.