The repository includes tests and the package provides a useful README, while recent publishing shows the project is not abandoned. Maintenance depends on one contributor, and the workflow uses two unpinned actions without a security policy.
68%
Total Score
50
100
93
75
All recent commits came from one contributor, so maintenance knowledge and release capability are concentrated in a single person.
The repository recorded one commit in the last 3 months from one active maintainer. Recent activity exists, but the very low volume provides limited evidence of sustained maintenance.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
v0.4.3 is not marked prerelease, although the package remains below a stable major version, which can imply greater API-change risk than a mature 1.x release.
The only workflow was fully analyzed with no high-confidence audit findings or unsafe untrusted triggers, but both action references are unpinned. That weakens build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.