The release is stable, documented, and lightweight, with a matching repository and no install-time scripts. Single-user ownership and the absent security policy leave less operational resilience, while the workflow needs tighter pinning.
64%
Total Score
50
100
100
50
The repository recorded zero commits and zero active maintainers during the last 3 months. That is a meaningful maintenance concern for a library, despite the broader release history and a recent recorded push.
The linked repository has no security policy. This reduces transparency about vulnerability reporting and maintainer response expectations, with no provided compensating security process.
The single workflow was fully analyzed and had no dangerous triggers, sinks, or audit findings, but all 8 action references are unpinned. Unpinned actions weaken build reproducibility and make workflow dependencies easier to change unexpectedly.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.