Clear documentation, tests, and a tiny dependency footprint reduce adoption friction. The repository is intact, licensed, and backed by automated dependency updates, though its small personal maintainer base limits resilience.
68%
Total Score
100
100
94
75
The package has five releases since 2013, but none in the last three years, which indicates a meaningful maintenance slowdown for a dependency.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented, though this is a modest transparency gap for a small package.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.