The package has a substantial README, release notes, repository tests, and a small dependency set. Its last registry release was over four years ago, the repository is archived, and the package is deprecated; its workflows also use an unpinned container image.
10%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption risk because future fixes and compatibility support are not expected.
The latest release was in December 2021, with no releases in the last 12 months. The established release history is outweighed by more than four years without a registry release.
The repository had zero commits and zero active maintainers in the last three months. This confirms that the package is not receiving current development attention.
The linked repository is archived, so active maintenance has ended even though it was pushed in February 2024. This strongly outweighs the otherwise useful source history.
Both workflows lack top-level permissions, which is common, and no untrusted triggers or script injection were found. However, the audit identified a high-confidence unpinned container image, leaving a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.