Clear documentation, release notes, and active testing make adoption easier. The main residual concern is reliance on one maintainer and weak workflow hygiene, so pin this version and watch for continuity.
67%
Total Score
67
100
93
67
The package declares MIT and includes license files, so it is licensed; the detected Apache-2.0 text alongside MIT is a minor declaration mismatch.
The repository is owned by a user rather than an organization, so the single-contributor concentration has no shown organizational handoff support.
All 95 recent commits came from one contributor, leaving maintenance highly dependent on a single person.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear.
All 28 analyzed action references are unpinned, and release.yml has a high-confidence template-injection finding plus top-level write permissions; the template finding alone is workflow hygiene rather than proof of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.