Tests, documentation, licensing, and a security policy provide a solid foundation. The release history and recent commit record show a young project that has gone quiet, while the unarchived organization-backed repository remains a useful positive.
58%
Total Score
75
81
75
The package has only two releases, with none in the last 12 months; its latest release was about 2 years ago. This materially raises abandonment risk despite the repository remaining available.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the concern raised by the long release gap.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of broad community adoption.
Version v0.0.5 is not a stable major release, so the API may still change and the project has limited release maturity.
The only workflow was fully analyzed, has read-only permissions, no high- or medium-confidence findings, and no untrusted checkout or script-injection paths. Three of six action references are unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0.0|^3.0.0 | — | — |
psr/cache Version ^3.0.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
psr/container Version ^2.0.0 | — | — |
psr/http-client Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.