It includes an MIT license, tests, a README, and no install-time scripts. The workflows need tighter pinning, and the project has no security policy.
58%
Total Score
50
86
67
The package has only five releases since September 2018 and none in the last 12 months; its latest release was published in April 2024. This indicates a long maintenance gap for a package consumers may still depend on.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap. The repository is not archived, but there is no recent activity showing active maintenance.
The repository has zero stars and forks and only one watcher, providing little independent evidence of community adoption or review. Popularity is supporting evidence, so this modestly lowers confidence in project maturity rather than determining the verdict.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a maintenance and disclosure gap, not evidence that the package is unsafe.
All seven analyzed action references are unpinned, and the audit found a high-confidence high-severity unpinned container image in the test workflow. No untrusted checkout or script-injection paths were found, limiting this to a workflow hygiene concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
railken/bag Version ^2.0 | — | — |
dompdf/dompdf Version ^2.0 | — | — |
rcrowe/twigbridge Version ^0.14.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.