The repository has no commits from any maintainer in the last three months, despite a recent release. Dependabot is enabled, but the sole workflow uses broad write access and leaves both action references unpinned; no security policy is provided.
68%
Total Score
83
100
100
83
There were zero commits and zero active maintainers in the last three months. This indicates a current maintenance pause and raises the risk that issues or compatibility changes may not receive prompt attention.
No repository security policy is provided. For a small package this is a transparency gap, though it is less severe than evidence of abandoned or unsafe release practices.
The sole workflow has a pull_request_target trigger without an untrusted checkout or script-injection sink, so that trigger is not dangerous here. However, both action references are unpinned and the workflow grants top-level write access, creating moderate workflow hygiene and permission concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos-ui Version ^7.3 || ^8.0 || ^9.0 | — | — |
matthieumastadenis/couleur Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.