The source includes a changelog and build tooling, and the owning organization provides clear repository backing. The workflow audit found all six action references unpinned, while no security policy or scanning is present.
57%
Total Score
100
81
83
The manifest declares a proprietary license, so the release is licensed, but the lack of a license file gives consumers less clarity than a repository license would.
The package has had no registry release in over three years, with zero releases in the last 12 months. This is a meaningful maintenance concern, although the linked repository was pushed more recently.
The repository uses Make and Composer build tooling, but it has no security scanning tools. That is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not severe on its own.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 6 of 6 action references are unpinned. The unpinned references create a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.