The package is well documented, licensed, and ships release notes for this version. Organization backing and a clean workflow audit offset the limited security process and narrow recent contributor base.
78%
Total Score
67
100
50
All recent commits came from one contributor, creating a narrow recent contributor base. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe risk.
Only one commit was recorded in the past three months, with one active maintainer. Recent release activity is reassuring, but this thin activity lowers confidence in sustained maintenance capacity.
The repository has no SECURITY.md or equivalent security policy. This is a transparency and response-process gap, though it is partly offset by the project's organization backing and other repository evidence.
The single workflow was fully analyzed with no injection, untrusted-checkout, or audit findings, and it scopes permissions at job level. Its one action reference is unpinned, a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
temporal/sdk Version ^2.0 | — | — |
internal/dload Version ^1.1 | — | — |
laravel/octane Version ^2.9 | — | — |
spiral/grpc-client Version ^1.0.0-rc1 | — | — |
spiral/roadrunner-kv Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.