The repository is correctly linked, licensed, documented, tested, and backed by an organization. Three workflow actions are unpinned, and the project has no security policy, reducing transparency and build hygiene.
68%
Total Score
75
100
93
67
The package has 11 releases since September 2020, but none in the last 12 months and its latest registry release was over a year ago. This indicates a meaningful maintenance slowdown despite a previously regular release interval.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed recently, the observed commit activity still suggests limited current maintenance capacity.
The linked repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The workflow audit found no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned. The workflow is complete and otherwise clean, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
october/rain Version ^4.0 | — | — |
composer/installers Version ^1.0 || ^2.0 | — | — |
vdlp/oc-redirect-plugin Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.