The package includes a clear README, changelog, license, and security policy. Recent repository activity and organization ownership provide continuity, but the short release history leaves limited evidence of long-term stability.
67%
Total Score
83
83
83
Only two releases exist, both on the same day, and the package is 143 days old, so there is limited evidence of sustained release maintenance.
One contributor made all five commits in the last three months, creating a genuine continuity risk; organization ownership provides some ability to hand off maintenance but does not show a second active contributor.
Version 0.0.2 is not a prerelease, but it remains below a stable 1.0 major, indicating a less mature compatibility commitment.
All six analyzed action references are unpinned, and four high-confidence findings identify floating or unpinned container images in integration and Playwright workflows. The workflows have no untrusted checkout or script-injection findings, limiting the risk to build reproducibility and workflow hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.22.0 | — | — |
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.