The project is mature, licensed, tested, and still publishes stable releases, but recent repository activity has stopped and its workflows rely on unpinned actions and floating container images. Missing security-policy documentation adds a smaller transparency concern.
68%
Total Score
75
100
100
50
There were no commits and no active maintainers in the last three months. Although the January push and December release provide some recent evidence, the current pause lowers confidence in ongoing maintenance.
The repository has no security policy. This is a modest transparency gap for reporting vulnerabilities, though it is partly offset by Dependabot-based security scanning.
All seven workflows were analyzed with no untrusted checkout or script-injection sink, so the findings are hygiene concerns rather than an immediate severe risk. However, all seven action references are unpinned, several workflows use floating latest container images, and one workflow has top-level write permissions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.