The project has a clear release trail and useful consumer documentation. One maintainer handles all recent commits, and workflow actions are not pinned, so continuity and build reproducibility deserve attention.
82%
Total Score
70
100
100
100
Only one registry account has publish access, which creates some release-continuity risk; the repository's recent activity confirms that this is also the sole active contributor.
The repository and registry are owned by the same individual account, so there is no organization backing to offset the concentrated maintainer base.
One contributor made all 13 commits in the last 3 months, leaving no demonstrated backup contributor and increasing continuity risk for a user-owned project.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout, injection, or audit findings. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.