Workflow pinning and the lack of a security policy add maintenance and review concerns. The project remains licensed, tested in its repository, and not archived, which supports continued use with care.
58%
Total Score
50
94
50
The package runs post-install and post-update Composer scripts, which adds install-time behavior that consumers should account for, although the signal does not show that the scripts are harmful.
The package has had only two releases, with the latest in August 2021 and none in the last 12 months, indicating a long maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of recent maintenance activity.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
All 23 analyzed action references are unpinned, and the audit found a medium-confidence template-injection pattern. No untrusted checkout or dangerous trigger was observed, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^2.8 | — | — |
thecodingmachine/safe Version ^1.3 | — | — |
wyrihaximus/react-mutex-contracts Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.