The README, matching repository, repository tests, and MIT license provide useful adoption and maintenance context. Three workflow actions are unpinned and no security policy is present, adding modest supply-chain hygiene concerns.
58%
Total Score
0
83
50
The package has had 5 releases since October 2017, but none in the last 12 months and the latest was published in December 2020, about 5 years and 9 months ago. This points to substantial abandonment risk despite the package's mature age.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, consistent with the release history showing no release since December 2020. The lack of recent activity materially lowers confidence in ongoing maintenance.
The repository has no security policy. This is a modest transparency gap for reporting vulnerabilities, but it does not by itself show that the package is unsafe to depend on.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or high-severity findings. However, all 3 action references are unpinned, leaving a modest reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sofa/eloquence-base Version >=5.5 | — | — |
sofa/eloquence-mutable Version >=5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.