Usable with caveats: the package is clearly licensed, documented, lightweight, and backed by a matching organization repository with tests and build tooling. It is brand new with only one release and no commits or active maintainers recorded in the last three months, so long-term maintenance is unproven.
68%
Total Score
75
100
88
63
One workflow uses pull_request_target, which warrants review because it can run with elevated repository context, although no untrusted checkout or script-injection pattern was detected.
This is a new package with one release published today, so there is no release track record from which to judge reliability or maintenance.
The repository records zero commits and zero active maintainers in the last three months. Because the package was released today, this may reflect its very recent creation, but ongoing maintenance is not yet demonstrated.
No security policy is present, leaving vulnerability-reporting expectations undocumented; this is a transparency gap for a new package.
Three workflows request top-level write permissions and one lacks top-level permissions, increasing workflow privilege exposure compared with a least-privilege setup.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.