The project has a long release history, clear organizational backing, and a documented release for this version. Recent repository activity is quiet, while all analyzed workflow references are unpinned and two workflows use unpinned container images.
70%
Total Score
67
100
93
50
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release and push provide some compensating evidence, current development activity is quiet.
There were no new or closed issues or pull requests in the last month, despite three open issues and two open pull requests. This is a modest sign of limited current responsiveness.
The project uses Composer and Make, but no security scanning tool was detected. This is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response. Organizational backing and ongoing releases partly compensate but do not remove the gap.
All 21 analyzed action references are unpinned, and two workflows have high-confidence unpinned-container findings. The pull_request_target trigger has no untrusted checkout or script-injection sink, but the workflow supply chain still has avoidable maintenance risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.