The project has stopped committing in the last three months, and every workflow action reference is unpinned. Its release notes, tests, documentation, security policy, licensing, and Composer security scanning provide useful supporting evidence.
68%
Total Score
75
94
75
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern for a young package. The recent release and non-archived status provide some evidence of prior activity but do not offset the current pause fully.
Version v0.3.0 is not on a stable major version, so the public API may still change. It is not a prerelease and recent releases contain no prerelease versions, which partly offsets the concern.
All 14 analyzed action references are unpinned, creating avoidable workflow supply-chain drift. The audit analyzed all three workflows, found no untrusted checkout or script-injection paths, and reported no high- or medium-severity findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/cache Version ^7.0 | — | — |
brick/date-time Version ^0.7 | — | — |
monolog/monolog Version ^3.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.