Clear licensing, repository tests, and a changelog improve adoption confidence. Workflow references are not pinned, and the security policy is absent.
66%
Total Score
83
94
50
The package is only 60 days old and published 46 releases within a single day, showing activity but little evidence of a settled release cadence.
All 5 recent commits came from one contributor, so maintenance continuity depends heavily on a single active person. Organization ownership provides some handoff capacity but does not remove the concentration.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All 11 analyzed action references are unpinned, which weakens build reproducibility. The auditor also reported a low-confidence cache-poisoning finding; because confidence is low and no untrusted trigger or checkout was found, that finding is hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.0 | — | — |
slim/slim Version ^4.0 | — | — |
phpunit/phpunit Version ^11.0 | — | — |
illuminate/testing Version ^11.0 || ^12.0 | — | — |
selective/test-traits Version ^2.0 || ^3.0 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.