The MIT license, matching repository, release notes, and organization backing make the package’s provenance clear. It has no install-time scripts, and its workflow audit found no unsafe patterns, though both workflow actions are unpinned.
58%
Total Score
75
83
75
The latest release was about four years and nine months ago, with no releases in the last 12 months. Only four releases exist, which points to limited ongoing release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. A push in 2024 shows the repository is not abandoned outright, but current maintenance activity is weak.
No repository security policy was found. This is a minor transparency gap, but it does not by itself indicate abandonment or make the release unfit.
The latest version is still in the 0.x series, so the package has not reached a stable major release. It is not marked as a prerelease, which partly offsets the maturity concern.
The single workflow was fully analyzed with no unsafe triggers, untrusted checkouts, script injections, or audit findings. Both of its two action references are unpinned, leaving a modest reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.8 | — | — |
symfony/browser-kit Version ^4.4 || ^5.0 || ^6.0 | — | — |
friends-of-behat/mink Version ^1.9 | — | — |
dmore/chrome-mink-driver Version ^2.7 | — | — |
behat/mink-selenium2-driver Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.