detect available port
60%
Total Score
75
100
81
67
The latest registry release was over eight years ago, with no releases in the last 12 months. That substantially lowers confidence in this specific release's maintenance, even though the package has a multi-year history.
The repository recorded no commits and no active maintainers in the last three months. Its recent push timestamp is some compensating evidence, but does not show sustained recent development.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly established. This is more concerning than a simple monorepo sub-package mismatch because both name and README evidence are absent.
No repository security policy was found, leaving vulnerability-reporting guidance less clear. This is a transparency gap rather than evidence of unsafe code.
All three workflows were analyzed without detected sinks or audit findings, and none grants top-level write permissions. However, all four action references are unpinned, so their versions can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^2.6.0 | — | — |
address Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.