The package is small and well-scaffolded, with clear licensing, tests, and a repository that matches its published purpose. It lacks a security policy and uses unpinned workflow actions, so extra maintenance review is warranted for long-lived projects.
60%
Total Score
50
100
90
83
The package has only 3 releases and none in the last 12 months; its latest release was over 3 years ago. This indicates limited ongoing maintenance, although a small testing utility may have a naturally slow cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and increasing abandonment risk.
No security policy was found in the repository. This is a transparency and response-process gap, though the package's narrow testing-focused scope limits its practical impact.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 3 action references are unpinned. The clean audit compensates for the missing permissions block, while unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.