The package includes a clear README, release notes, tests in the repository, licensing files, and a security policy. Its workflow references are all unpinned, and the license scan also finds GPL-3.0 alongside the declared LGPL-3.0-or-later, which deserves clarification.
64%
Total Score
50
100
79
83
The artifact contains license files and the repository also has a license, but detection includes GPL-3.0 alongside the declared LGPL-3.0-or-later; the relationship should be clarified before broad adoption.
Only one release exists, published 459 days ago, with no releases in the last 12 months; this materially limits evidence of sustained maintenance.
No commits and no active maintainers were recorded during the last three months, weakening the otherwise positive evidence from the recent repository push.
Version 0.1.0 is not a stable major release, so its API and behavior may still change even though it is not marked as a prerelease.
All 19 action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings are low-confidence hygiene warnings, while the audit itself analyzed all workflows and found no untrusted checkout or script-injection paths.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
brick/math Version ^0.13.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
identifier/identifier Version ^0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.