The repository has basic tests, release notes, and security scanning. One contributor and a single release limit confidence in long-term support, while workflow permissions and bot checks need attention.
60%
Total Score
50
100
94
50
Only one release exists, published 202 days ago, so there is little release history to establish sustained maintenance.
All recent commits come from one contributor, leaving no demonstrated backup maintainer and increasing continuity risk for a user-owned project.
The repository recorded one commit in the last three months from one active maintainer; recent activity exists, but the pace is too thin to demonstrate sustained maintenance.
No repository security policy was found, so consumers have no documented channel for reporting vulnerabilities or receiving coordinated fixes.
All four workflows were analyzed, but every action reference is unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.