The package has a matching organization-backed repository, MIT licensing, tests, release notes, and no install-time scripts. Maintenance has slowed since the last registry release, while all seven workflow actions are unpinned and the repository lacks security scanning and a security policy.
68%
Total Score
88
100
89
83
The package has six releases over about 3 years and 10 months, but none in the last 12 months; this indicates a slower release cadence and some maintenance uncertainty.
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of active maintenance despite the recent push date shown elsewhere.
Composer is used for the build, but no security scanning tools are configured, leaving a meaningful security-hygiene gap.
The repository has no security policy. The README provides a security contact, which partly compensates for the missing formal policy but does not provide documented handling guidance.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all seven action references are unpinned, so workflow dependencies can change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.2 | — | — |
zaphyr-org/utils Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.