Automated tests, a clear MIT license, and a security policy improve transparency. GitHub Actions use unpinned dependencies and install packages outside lockfiles, adding avoidable build-hygiene risk.
56%
Total Score
50
79
100
The package has 27 releases and historically released about every 12 days, but it has had no registry release in roughly four years. That strongly lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being roughly two years ago. This is meaningful abandonment risk, though the repository is not archived.
This is still a release candidate, despite being the latest version and part of a stable major line. Consumers should expect less finality than from a stable release.
All nine workflows were analyzed with no untrusted checkouts, script injection, or high- or medium-severity findings. However, all 35 action references are unpinned and two workflows install packages outside lockfiles, creating avoidable reproducibility and supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^1.1 | — | — |
google/protobuf Version ^3.3 | — | — |
kreait/firebase-php Version ^5.0 || ^6.0 | — | — |
google/cloud-firestore Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.