git@github.com:stalniy/ucast.git
78%
Total Score
healthy
Healthy release with current maintenance and provenance; single-maintainer activity and unpinned workflow actions add caveats.
All 3 recent commits came from one contributor, leaving maintenance dependent on a single active person.
Only 3 commits were made in the last 3 months, showing some recent activity but a modest maintenance pace.
The project uses TypeScript build tooling, but no repository security-scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Both workflows were analyzed cleanly with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 4 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@ucast/core Version 2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.