The project has tests, a clear MIT license, organization backing, and security tooling. Its long release gap, absent recent commits, and unsafe workflow pinning create meaningful maintenance and build-transparency concerns.
58%
Total Score
75
100
86
67
All eight analyzed action references are unpinned, and the audit found a high-confidence high-severity unpinned container image. The workflows were fully analyzed and use no untrusted triggers or checkout sinks, which limits but does not remove the provenance concern.
The package has 20 releases, but none in the last 12 months and its latest release was in January 2024, indicating substantially slowed maintenance.
There were no commits and no active maintainers in the last three months, reinforcing the concern raised by the absence of recent releases.
The assessed version is presented as v1.0.11, while the collected latest registry version is 0.4.4; this inconsistency reduces release metadata confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version >=1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.