The template is small and clearly matched to its repository, with tests and a working CI workflow. Its two workflow actions are unpinned, and no security policy is published.
43%
Total Score
50
100
70
67
Only two releases were published, with the latest more than seven years ago and none in the last 12 months. This is strong evidence of an effectively inactive release line.
The repository had zero commits and zero active maintainers in the last three months, reinforcing the long release gap and increasing abandonment risk.
The repository is not archived, which is a positive administrative status, but its last push was more than six years ago and does not offset the inactivity shown by release and commit history.
The repository has no published security policy. For a small template this is a modest transparency gap rather than a severe dependency risk.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.