88%
Total Score
healthy
Active organization-backed project with signed provenance and strong release cadence; repository-package linkage is the main transparency gap.
Four of five publishing accounts use the organization domain, consistent with the organization-backed project. The outside-domain account jameshenry (henry.sc) is a minor account-hygiene caution, not evidence of limited maintenance capacity.
The repository name does not match this platform-specific package and its README does not mention the package, leaving a transparency gap about the exact package-to-repository relationship. The mismatch is understandable for a monorepo subpackage but is still worth noting because neither check matched.
All 13 workflows were analyzed with no untrusted checkouts or script injections, and all 81 action references are pinned. High-confidence template-injection findings and low-confidence cache findings remain workflow hygiene concerns, but no trigger-and-sink combination makes them severe here.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.