The package is feature complete, tested, licensed, and recently released, but maintenance is intentionally infrequent. The workflow audit also found a high-confidence bot-condition issue and all five actions are unpinned.
65%
Total Score
83
100
89
75
Only five releases have been published since December 2021, with a median interval of about 449 days and one release in the last 12 months. This fits a feature-complete package but indicates sparse maintenance.
The repository had zero commits and zero active maintainers in the last three months. Recent release activity partly offsets this, but the absence of coding activity raises maintenance risk.
The repository has no stars or forks and only two watchers, indicating a small user base. Popularity is supporting evidence rather than a health verdict, so this has limited weight.
The repository has no security policy, leaving vulnerability-reporting guidance undocumented. This is a modest transparency gap for a maintained library.
The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, and all five action references are unpinned. There are no untrusted checkouts or script injections, which limits the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.