Core interfaces, types, and crypto abstraction for otplib
78%
Total Score
healthy
Healthy release with active maintenance and strong provenance, tempered by concentrated ownership and workflow template-injection findings.
The repository is owned by an individual rather than an organization, so the concentrated recent commit activity represents a genuine continuity concern rather than normal organizational delegation.
Two contributors were active, but one made 16 of 17 recent commits, leaving maintenance heavily concentrated despite the second contributor's presence.
All seven workflows were analyzed, all 58 action references are pinned, and permissions are read-only. However, two high-confidence template-injection findings in mutation.yml and tag-release.yml are meaningful workflow hygiene concerns, even though no untrusted checkout or script-injection trigger was detected.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.