The package includes a substantial README, changelog, and test suite, and it is backed by an organization-owned project. Workflow permissions are broad and its single action reference is unpinned, while repository security scanning and a security policy are absent.
64%
Total Score
75
100
75
67
This release is the package's only release, published 0 days ago, so there is no track record for maintenance or release reliability yet.
The repository shows 0 commits and 0 active maintainers over the last 3 months. Because the package is newly published and described as a synchronized mirror, this is a maintenance concern but not conclusive abandonment evidence.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but popularity is not required for a small, newly published plugin and does not decide the assessment.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
testo/testo Version 0.10.49 - 1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.