The project has clear documentation, release notes, security reporting, and organization backing. Its license files conflict with the MIT manifest, and the workflow uses two unpinned actions; pin this version and verify licensing before adoption.
72%
Total Score
67
93
83
The artifact contains a GPL-2.0 license file, while the manifest declares MIT; the repository also has a license file. The conflicting declarations create a real licensing clarification need.
All one recent commit came from a single contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this signal.
Only one commit was recorded in the last three months, indicating limited recent development activity. The recent release and current repository state provide some compensation, but maintenance momentum remains thin.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or injection findings. However, both of its two action references are unpinned, leaving avoidable dependency-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bugsnag/bugsnag Version ^3.30.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.