Strong tests, documentation, release notes, and an organization-backed repository support dependable maintenance practices. The workflows use all 8 actions without pinning and reference archived actions, while the lack of recent commits adds ongoing maintenance risk.
68%
Total Score
75
100
94
67
The package has 8 releases since January 2021, but none in the last 12 months and the latest release was about 20 months ago. This is meaningful evidence of slowing maintenance, despite a previously regular median release interval of about 62 days.
There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last year, this lowers confidence in ongoing maintenance.
No security policy is present in the repository. This is a modest transparency gap for reporting vulnerabilities, but it is not by itself evidence of abandonment.
All 8 analyzed action references are unpinned, and both workflows use archived actions with high-confidence medium-severity findings. There are no untrusted checkouts, script injections, or top-level write permissions, which limits the impact to workflow hygiene rather than a severe supply-chain concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wsdltophp/domhandler Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.