Its MIT license, small dependency surface, and complete README make the code easy to inspect. Repository tooling and a security policy help, but the workflow audit found a high-confidence bot-condition issue and an unpinned action.
42%
Total Score
75
100
78
83
The last registry release was in May 2022, with no releases in the following four years. That sharply raises abandonment and stale-dependency risk despite a history of 22 releases.
The package includes a README, changelog, and release notes for this version, but the README explicitly says the repository will become read-only because the package was integrated into another project.
There were no commits and no active maintainers in the last three months. The recent repository push offsets this only partly and does not restore package release activity.
The repository has one star and no forks, indicating limited external adoption. Popularity is supporting evidence only, but it offers little compensating evidence for the stalled release history.
The only workflow has a high-confidence bot-conditions finding, uses write permissions at the workflow level, and leaves its single action unpinned. No untrusted checkout or script injection was found, so this is a hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.