Clear documentation, repository tests, and a matching license make integration and provenance easy to check. Pin the four currently unpinned workflow actions before relying on its release automation.
66%
Total Score
67
88
50
This is the first release, published today, with no established release cadence yet. The lack of history limits maturity evidence but is not by itself an abandonment signal for a new package.
One contributor made all three recent commits, concentrating maintenance in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has three commits in the last three months, all within the current launch period. Activity is present, but there is not yet enough history to demonstrate sustained maintenance.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap rather than evidence that the package is unsafe.
All four analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkout, script injection, excessive permissions, or other higher-risk workflow findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1 | — | — |
amphp/socket Version ^2.3 | — | — |
thesis/grpc-retry Version ^0.1.2 | — | — |
open-telemetry/api Version ^1.10 | — | — |
open-telemetry/sdk Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.