Tests, release notes, a license, and static analysis provide solid consumer and maintenance coverage. The tiny project footprint and inactive recent commit window make long-term support less certain.
69%
Total Score
50
100
88
75
The package has existed for over five years with 18 releases, but only 1 release in the last 12 months; this suggests a slower cadence while still showing an established release history.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance despite a recent push being recorded elsewhere.
The repository has 1 star, 0 forks, and 1 watcher, so there is little external adoption evidence. Popularity is supporting evidence only and does not outweigh the package's other maintenance signals.
No security policy was found, leaving vulnerability-reporting expectations unclear. This is a transparency gap rather than evidence of unsafe code.
All 17 analyzed action references are unpinned, reducing build reproducibility and increasing exposure to upstream action changes. The audit found no dangerous triggers, script injection, or other reported findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/strings Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.