The repository lacks a security policy, and all seven workflow actions are unpinned. Clear licensing, documentation, tests, changelog support, and matching project ownership provide useful transparency.
63%
Total Score
50
90
50
There have been no registry releases in about 14 months, despite a prior median interval of about 14 days, indicating a meaningful slowdown in maintenance.
The repository recorded no commits and no active maintainers in the past three months, which adds abandonment risk even though the repository is not archived.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations undocumented.
The workflow audit analyzed all one workflow with no high-confidence findings or unsafe trigger sinks, but all seven action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
decodelabs/coercion Version ^0.3 | — | — |
decodelabs/exceptional Version ^0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.