Maintenance is currently quiet, with no active maintainers or commits in the last three months, and all four workflow actions are unpinned. Tests, release notes, licensing, and a matching repository provide useful evidence of basic project discipline.
64%
Total Score
75
94
75
The repository recorded 0 commits and 0 active maintainers in the last three months, which raises a genuine maintenance and abandonment concern. A release was still published within the observed history, partly offsetting the inactivity.
The repository has 0 stars and 0 forks, with 1 watcher, so there is little visible community adoption or external review. Popularity is supporting evidence only and does not outweigh the package's concrete maintenance signals.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene gap rather than evidence that the package is unsafe.
All 4 analyzed action references are unpinned, leaving workflow dependencies exposed to unexpected upstream changes. The audit found no dangerous triggers, untrusted checkouts, script injection, or other reported findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
symfony/yaml Version ^7.3 | — | — |
psr/container Version ^1.1|^2.0 | — | — |
symfony/config Version ^7.3 | — | — |
monolog/monolog Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.