The repository includes a real test suite, release notes, and a clear license, but the project has no operating history yet. All six workflow actions are unpinned, and no security policy is published.
68%
Total Score
75
100
88
75
This is a brand-new package with two releases published within one day, so there is not yet enough history to demonstrate sustained maintenance. The stable v1.0.0 release and accompanying notes provide some maturity evidence.
There were no commits and no active maintainers during the measured three-month window. Because the repository is newly created, this is mainly a lack of track record rather than evidence of abandonment.
The repository uses Composer and Make for build tasks, but no security scanning tool was detected. For a small package this is a modest transparency and maintenance gap.
No security policy is published in the repository, leaving vulnerability reporting and response expectations unspecified.
Both workflows use read-only permissions and the audit found no dangerous triggers, untrusted checkouts, or injection findings. However, all 6 of 6 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.