The package has a clear MIT license, a substantial README, repository tests, and release notes for this version. Both workflow actions are unpinned and the repository has no security policy, adding avoidable maintenance friction.
12%
Total Score
0
80
67
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent release history does not compensate for the absence of ongoing source activity.
The linked repository is archived even though it was last pushed about 115 days ago, so the source is no longer expected to receive normal maintenance. This is a severe abandonment risk for a native concurrency engine.
No security policy was found in the linked repository. This weakens vulnerability-reporting transparency, although it is secondary to the repository being archived.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but both of its 2 action references are unpinned. That leaves avoidable build reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cloudtay/ripple-kernel Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.