Long release history, frequent recent releases, and complete package documentation support confidence. The organization-backed repository remains active, though it lacks a security policy and has a workflow image using the floating latest tag.
78%
Total Score
100
100
100
75
No security policy was found in the linked repository, leaving vulnerability-reporting expectations and disclosure procedures less transparent.
All three workflows were analyzed and no untrusted checkout or script-injection paths were found, but one high-confidence finding reports a container image using the floating latest tag; two of five action references are also unpinned.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.