The source is not archived, has organization backing, and provides release notes for this breaking change. Workflow references are all unpinned, adding supply-chain hygiene risk despite no audited workflow findings.
18%
Total Score
50
50
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level abandonment is a severe dependency risk even though the repository is not archived.
The package has had no releases in the last 12 months, despite a prior median interval of about 12 days. This indicates a sharp interruption in publishing activity.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the absent releases, this supports a strong maintenance concern.
Both workflows were analyzed without high-confidence findings or untrusted checkout and script-injection issues. However, all 7 action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
x-wp/di-implementation Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.