Tests, a useful README, and organization backing reduce adoption risk. Maintenance has gone quiet since the last release, and the workflows use unpinned actions; pin this version if you adopt it.
64%
Total Score
75
88
67
The package has had only two releases, with no release in the last 12 months; the latest release was about 22 months ago. This is a meaningful maintenance concern, though the package is not deprecated and remains on a stable major version.
There were no commits and no active maintainers in the past three months. This supports the concern that maintenance has slowed, although the repository was pushed more recently than the package's last registry release.
The project uses Composer for its build process, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap rather than a severe dependency risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene concern, not evidence that the package is unsafe.
Both analyzed workflows use unpinned actions, which weakens build reproducibility. The audit found no dangerous triggers, untrusted checkouts, script injection, or excessive top-level permissions, which limits the impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.