Clear documentation, licensing, tests, and release notes support dependable use. Maintenance is active, though most recent commits come from one contributor and workflow actions are not pinned.
78%
Total Score
83
100
50
One contributor made 23 of 24 recent commits, creating meaningful concentration risk. Organization backing and a second active contributor partly compensate, so this is a caution rather than a severe maintenance failure.
The repository has no published security policy, leaving reporting and response expectations less transparent for consumers.
All 19 analyzed action references are unpinned, and two high-confidence medium-severity findings use archived actions. The workflows have no untrusted checkout or script-injection findings, and no top-level write permissions, which limits the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.