Repository tests, release notes, and Psalm scanning provide useful maintenance evidence. Organization backing and a clean package structure help, but the project offers limited security-process transparency.
58%
Total Score
75
80
50
The package has had no releases in over two years, despite only two releases overall. This materially raises abandonment and freshness concerns.
The repository recorded no commits and no active maintainers in the past three months, reinforcing the concern from the stalled release history.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a dependency.
The workflow audit is complete and found no dangerous triggers, sinks, or severity-rated findings, but all 16 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.