The package is clearly licensed, documented, tested, and has no install-time scripts. Its one-person project has had no commits in the past three months, and all three workflow actions are unpinned, leaving maintenance and build-integrity concerns.
67%
Total Score
50
100
92
75
Only two releases were published, both about 14 months ago, with no releases in the past 12 months. That is a meaningful maintenance concern, though the stable v1.1 release and recent repository push provide some compensation.
The repository recorded zero commits and zero active maintainers in the past three months. This weakens evidence of ongoing maintenance, despite the repository not being archived.
The repository has no security policy. For a small library this is a transparency gap rather than a severe adoption blocker, but it leaves vulnerability-reporting expectations unclear.
The single workflow was fully analyzed with no trigger or audit findings, but all three action references are unpinned. That weakens build reproducibility and makes future action changes harder to control.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.