A single maintainer and no recent activity limit confidence in ongoing fixes. The package is small, tested, licensed, and has release notes, but its workflows use an unpinned container image.
58%
Total Score
50
100
90
67
One registry maintainer is responsible for publishing this package. Combined with the lack of recent repository activity, this leaves limited visible capacity for continued maintenance.
The package has had only 3 releases, with the latest published in April 2023 and none in the last 12 months. This indicates prolonged release inactivity for a dependency that may need compatibility updates.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push being in October 2023. That weakens evidence of ongoing maintenance.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is not evidence of a vulnerability itself.
Both workflows were analyzed successfully, but all 4 action references are unpinned and the audit found a high-confidence unpinned container image. This creates avoidable build-reproducibility and workflow supply-chain risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.