This release shows strong operational activity and reasonable baseline hygiene: it is not deprecated, has a stable major version, a license, tests, a changelog, no install-time lifecycle scripts, active organizational backing, substantial recent commit activity, security tooling, and a security policy. However, the package is only 37 days old, its linked repository is the organization-wide `.github` repository rather than a package-specific repository and does not mention `hydra-gates`, which creates a meaningful transparency and provenance concern. Workflow script-injection findings and incomplete or broad GitHub Actions token-permission declarations add security-maintenance caution, while the high concentration of commits in one contributor modestly increases continuity risk despite the organization and other active contributors. It is usable, but I would verify the package-to-source relationship and CI release controls before making it a critical dependency.
68%
Total Score
90
100
81
75
The linked repository name does not match the package and its README does not mention `hydra-gates`, so the source relationship is not transparently established and the package may be using an unrelated organization repository.
All 21 workflows were analyzed with no pull-request-target or untrusted-checkout findings, but two workflows contain script-injection patterns, creating a concrete CI security-hygiene concern.
Thirty releases in the first 37 days indicates active publishing, but the very short history and median interval of about 10 hours leave limited evidence of long-term maturity.
The repository is highly active, with 70 new issues, 30 closed issues, 4 new pull requests, and 302 merged pull requests in one month; the open-issue imbalance warrants some caution about backlog management.
Nine workflows use job-level permissions only, ten lack top-level permissions declarations, and two declare top-level write access; although nine workflows are read-only, the inconsistent and sometimes broad permission posture merits caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.