Documentation and automated checks are in place. The project is young with only one release, and recent work comes from one contributor; all three workflow actions are also unpinned. Organization backing and Dependabot reduce, but do not remove, the maintenance concerns.
68%
Total Score
67
94
75
The package is only 57 days old and has one release, so its long-term maintenance pattern is not yet established.
One contributor made all 2 recent commits, concentrating maintenance risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
There were only 2 commits in the last 3 months, although the recent push shows some ongoing activity; this is limited evidence of maintenance capacity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The audit completed cleanly with no dangerous triggers or findings, but all 3 referenced actions are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.