It has clear licensing, a usable README, and a small dependency footprint. Organization backing and frequent releases help, but maintenance depth and CI supply-chain hygiene remain limited.
70%
Total Score
75
100
88
75
No commits and no active maintainers were recorded in the last three months. The frequent release history partly offsets this, but the lack of recent development activity lowers confidence in ongoing maintenance depth.
The repository has 4 stars, 0 forks, and 3 watchers. Low popularity is only supporting evidence and does not outweigh the package's long release history, but it provides little external evidence of maturity.
Composer is used as the build tool, but no security-scanning tool was detected. This is a modest transparency and maintenance-hygiene gap rather than evidence of an unsafe release.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear. This is a documentation gap, not a direct indication of package compromise.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 3 of 3 action references are unpinned, which weakens CI reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
windwalker/utilities Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.