Tests, a changelog, release notes, and a matching repository provide useful transparency. The MIT license and small dependency set are solid, but missing security scanning and several unpinned workflow actions reduce confidence in project hygiene.
55%
Total Score
50
100
83
50
The package has only one release, published about 11 months ago, so there is little release history to demonstrate sustained maintenance.
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful maintenance concern for a package with only one release.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
This is a prerelease alpha and all recent releases are prereleases, indicating an immature API and higher change or abandonment risk.
Both workflows were analyzed successfully with no dangerous triggers or audit findings, but three of four action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.