Healthy and suitable to install. It is actively developed by a broad contributor group, clearly documented, tested in the repository, and has no runtime dependencies or install scripts. The main caveats are missing build attestation and a security policy, plus one workflow with broad write permissions.
92%
Total Score
90
100
100
80
50
No build attestation, trusted publisher identity, or staged publishing is present, leaving the relationship between the source and published artifact less independently verifiable.
The repository has recent issue and pull-request activity, though 24 new issues and pull requests versus only 6 closures or merges in the last month indicate some backlog pressure.
The repository has no published security policy, which makes vulnerability reporting and coordinated disclosure less transparent despite the presence of CodeQL scanning.
Three workflows declare read-only permissions, but the CodeQL workflow has top-level write permissions, creating a broader-than-minimal workflow access surface.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.