The repository has no recent commits and its workflows leave all 15 action references unpinned; it also lacks a security policy. The MIT license, tests, and release notes are positives, but they do not offset the package-wide abandonment status.
12%
Total Score
0
57
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-wide deprecation is a severe adoption risk even though the specific release is stable.
Only two releases have been published, with no release in about 4 years and 10 months. The long gap supports the abandonment concerns rather than showing an actively maintained package.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is consistent with the archived state and leaves little evidence of ongoing maintenance capacity.
The linked repository is archived, and its last push was about 2 years and 9 months ago. This strongly indicates that maintenance and issue response should not be expected.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This matters more for a package whose repository is already archived and shows no current maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.