The package is well documented, tested, and licensed, with no install-time scripts. Its single workflow has no dangerous trigger or audit finding, but one dependency reference is unpinned.
45%
Total Score
25
100
83
75
Only five releases are recorded, with the latest about six years ago and none in the last 12 months. This is strong evidence of abandonment risk despite the package remaining published.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long release gap and indicating no recent maintenance capacity.
There has been no issue or pull request activity in the last month, with one issue still open. This adds modest evidence of limited ongoing stewardship.
The repository has no security policy. For a small package this is a transparency gap, although the absence of reported workflow audit findings partly limits the concern.
The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, its only action reference is unpinned, leaving a small reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.