UAEPP extension provided by Hostmaster (https://hostmaster.ua/).
68%
Total Score
caution
Usable with caveats: no registry release in about 20 months and maintenance depends on one contributor.
Only one registry account has publish access. That is consistent with the single-person repository ownership and increases continuity risk, though it is not evidence of unsafe code.
The package has only 5 releases since 2017 and none in the last 12 months; its latest registry release was about 20 months ago. This is partly offset by a repository commit in the last 3 months, but the release cadence still raises maintenance risk.
All recent commits came from one contributor, leaving the project dependent on a single person for ongoing maintenance. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset this concentration.
The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities. This is a documentation gap rather than evidence of a vulnerability.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or injection findings. However, all 3 action references are unpinned, leaving the build exposed to future action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | ~2.0 | ~3.0 | — | — |
struzik-vladislav/epp-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.