The MIT license, stable versioning, small dependency footprint, and clear README support adoption. Maintenance has gone quiet, with no recent commits or releases, while workflow references are all unpinned and no security policy is published.
58%
Total Score
75
100
88
67
The package has 22 releases, but none in the last 12 months; the latest release was about 18 months ago. This points to reduced maintenance activity, although the release history is established.
There were no commits and no active maintainers in the last 3 months. Combined with the absence of releases in the last 12 months, this materially raises abandonment risk.
The repository uses Composer build tooling, but no security scanning tool was detected. The missing scanner is a modest transparency and hygiene gap, not evidence of unsafe code.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed without dangerous triggers, sinks, or audit findings, but all six action references are unpinned. That leaves avoidable workflow supply-chain exposure, while the lack of top-level permissions is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.