The package has tests, an MIT license, and organization-backed ownership, but its consumer documentation is missing and its workflow dependencies are unpinned. The small dependency set and read-only workflow permissions reduce the practical risk.
68%
Total Score
75
100
86
67
The artifact includes tests and has a GitHub release for this version, which supports basic project discipline. The missing README reduces consumer transparency for a library, while the absent changelog is normal for a first release.
This is the first release, published today, so there is no release track record yet; the lack of history is a maturity concern rather than evidence of abandonment.
The repository has no commits in the last three months and no active maintainers in that period, but the package and repository were created today, so this mainly reflects limited evidence of maintenance capacity.
The repository has no security policy, which leaves vulnerability-reporting expectations undocumented. This is a transparency gap, not a severe dependency risk by itself.
The workflow was fully analyzed, has read-only permissions, and has no dangerous findings. However, both of its action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skorp/detect-incompatible-samesite-useragents Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.