The source repository includes tests, release notes, a matching README, and dependency scanning. Its small contributor base and three unpinned workflow actions leave some maintenance and build-integrity risk.
78%
Total Score
67
100
50
The package and repository are owned by the same individual, so the source link is coherent, but there is no organization backing to offset the concentrated contributor base.
All four recent commits came from one contributor, so maintenance is concentrated and continuity depends heavily on that person.
No repository security policy was found. This is a transparency gap, though it is partly offset by the repository's Dependabot scanning.
The only workflow has read-only permissions and no audited dangerous findings, but all three action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.