Its workflow uses two unpinned actions, and the repository has no security policy. The package is only about two minutes old, so maintenance capacity and adoption remain unproven.
62%
Total Score
75
83
67
The package is about two minutes old and has only two releases, so there is not yet enough history to demonstrate sustained maintenance or stability.
The repository has no commits or active maintainers in the last three months; its very recent creation explains this, but maintenance capacity is still unproven.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response for a package that handles authentication, permissions, and tokens.
The single workflow was fully analyzed and uses read-only permissions with no audit findings, but both of its two action references are unpinned, leaving them exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.4 | — | — |
psr/container Version ^2.0 | — | — |
ssmiff/entabula Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.