Clear documentation, licensing, and a small dependency set make the package straightforward to evaluate. Its workflow hygiene is weak, and the long release gap limits confidence in continued maintenance.
56%
Total Score
50
100
86
75
The package has had only three releases, with none in the last seven years and a median release interval of about three years. This is a meaningful maintenance concern, although the repository is still active enough to offset abandonment risk somewhat.
There were no commits and no active maintainers in the three months measured. Combined with the old latest release, this lowers confidence in ongoing maintenance.
The repository uses Make and Composer, showing build tooling, but no security scanning tools are present. The missing scanning is a hygiene concern rather than a severe dependency risk.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified.
Both workflows analyze successfully and avoid untrusted triggers and script-injection sinks, but all nine action references are unpinned. The audit also found two high-confidence artipacked findings in CI because checkout credentials are not explicitly disabled, creating notable workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
textpattern/lock Version >=4.6.0 | — | — |
textpattern/installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.