Clear licensing, tests, and a matching repository support straightforward maintenance. Releases and commits have stopped, while workflows use unpinned actions and install scripts run.
58%
Total Score
50
100
93
67
The package declares post-autoload-dump, post-install-cmd, and post-update-cmd scripts, so installation and updates execute package-defined commands. This adds operational review cost even without evidence of malicious behavior.
The package has had no release in roughly two years: its latest release was October 17, 2024, despite seven releases overall. That materially raises abandonment risk, although the package is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the prolonged release gap. This weakens evidence of ongoing maintenance.
The linked repository has no security policy. That leaves vulnerability-reporting and response expectations unclear, though the repository otherwise provides tests and documentation.
All 20 analyzed action references are unpinned, and one workflow grants top-level write permissions; no untrusted checkout or script-injection path was found. The audit was complete, but the workflow hygiene is still a maintenance and supply-chain caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
linkorb/xuid Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.