The package includes a clear README, an Apache-2.0 declaration, and read-only workflow permissions. Its small repository has little supporting process, including no security policy and unpinned action references.
62%
Total Score
0
86
67
There were zero commits and zero active maintainers in the last three months, consistent with the repository having stopped receiving changes since September 2023. This materially raises abandonment risk.
The package has 26 releases, but none in the last 12 months and its latest release was on September 1, 2023. This indicates a long maintenance gap for a package that may still be relied upon.
Composer build tooling is present, but the repository reports no security-scanning tools. That is a modest process gap rather than evidence of an unsafe release.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency for a package that runs scheduled commands and processes.
The single workflow was fully analyzed, uses read-only permissions, and has no reported audit findings, but both of its two action references are unpinned. Unpinned references are a workflow hygiene risk without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^4.4|^5.4|^6.0 | — | — |
nikic/fast-route Version ^1.3 | — | — |
workerman/crontab Version ^1.0 | — | — |
workerman/workerman Version ^4.0 | — | — |
yzh52521/think-lock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.