The package includes useful documentation, tests, a changelog, and a matching source repository. Missing security scanning and five unpinned workflow actions add further maintenance risk.
38%
Total Score
0
70
50
The package has had 34 releases but none in the last four years; its latest release was on July 27, 2022, showing prolonged release inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release pause and limited maintenance capacity.
The release includes a LICENSE file and the repository also has one, but the artifact declares GPL-3.0-or-later while the detected license is GPL-3.0, creating a minor scope mismatch.
The repository has no security policy and no security scanning tools, reducing transparency and making vulnerability reporting and detection less clear.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, but all five referenced actions are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
warlof/seat-connector Version ^2.0 | — | — |
socialiteproviders/discord Version ^v2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.