The project has organization backing, a matching repository, release notes, tests in the source tree, and a readable README. The MIT declaration conflicts with the GPL-3.0 license file, and its workflow uses two unpinned actions without security scanning.
48%
Total Score
50
100
75
67
The latest release was in October 2021, with no releases in the last 12 months, despite nine releases overall. This long release gap is a substantial maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was in March 2023. That supports a strong abandonment concern, although the repository is not archived.
The package declares MIT, but the included LICENCE.md was detected as GPL-3.0. The presence of a license file is positive, but the mismatch creates a real obligation and compatibility concern.
The linked repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less significant because the project is small and the workflow audit found no high-severity issues.
The single workflow was fully analyzed with no dangerous sinks or audit findings, but both of its two action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions remain a minor reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bristol-su/support Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.