The repository is active and the package is clearly licensed. Organization backing helps offset its concentrated contributor activity, but the automation needs tightening before production use.
68%
Total Score
100
81
50
The package is young at 172 days with three releases and a median interval of about 86 days. That shows real release activity, though the limited history leaves maturity less established.
The project uses build tooling, but no security-scanning tools were detected. For a native extension this leaves a meaningful quality and maintenance gap.
No repository security policy was found. This reduces disclosure transparency, although it does not by itself indicate abandonment.
Version 0.4.0 is not a prerelease, but it remains before a stable 1.0 major release. This is a modest maturity consideration rather than a severe stability concern.
All 33 analyzed action references are unpinned, and two workflows grant top-level write permissions, creating avoidable automation hygiene risk. The release workflow has high-confidence template-injection findings, but no untrusted checkout or script-injection trigger was reported; the low-confidence cache findings are hygiene only.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.