Usable with caveats: the release is clearly documented, licensed, backed by a matching organization repository, and has tests and automation. It is brand new with only one v0.1.0 release, while workflow permissions and the absence of a security policy merit review before adoption.
70%
Total Score
75
100
83
70
Six workflows were analyzed with no untrusted checkouts or script injection, but one pull_request_target workflow is used for Dependabot auto-merge and warrants careful review.
This is a new package with one release published 0 days ago, so there is not yet enough release history to demonstrate long-term stability.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository was only pushed 0 days ago; this is an early-maturity limitation rather than evidence of abandonment.
The repository has no stars, forks, or watchers, but the package is 0 days old, so the absence of popularity is expected and only limits external validation.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.