Parse yes/no like values
82%
Total Score
75
100
89
88
50
No build attestation or trusted-publisher provenance is available, so consumers have less evidence about how this release was produced.
The package has existed for about 12 years with 11 releases, but the latest release was about 13 months ago and there were no releases in the last 12 months. This indicates a mature, mostly quiet project rather than clear abandonment.
There were no commits or active maintainers in the last three months. For this small, mature package the quiet period is a maintenance caution, not evidence of abandonment by itself.
The repository reports no build tool or security-scanning tool. The package is small and directly structured, so this is a modest transparency gap rather than a severe concern.
All workflows were analyzed with no detected injection or high-confidence security findings, but both action references are unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.