A quiet repository and a thin one-person publishing base reduce confidence in continued maintenance. The project has tests, release notes, security tooling, and no deprecation or install-time scripts, but workflow safeguards need tightening.
68%
Total Score
50
100
94
75
All three workflows were analyzed, but all 9 action references are unpinned and a high-confidence template-injection finding may expand attacker-controlled input into code. Top-level write permissions in one workflow add mild exposure, although no untrusted checkout or script-injection path was found.
One registry publishing account provides a limited publishing base; this is a maintenance-capacity concern for a user-owned project, though it does not by itself indicate abandonment.
The registry namespace and repository are owned by the same individual, confirming alignment but not organizational backing or redundancy.
There were no commits and no active maintainers in the last three months, indicating a quiet development period; the recent push shown by repository status is a partial counterweight but not evidence of sustained activity.
No repository security policy is present, leaving disclosure guidance undocumented; the repository's Dependabot and Psalm tooling partly compensates for this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.