A single contributor makes the maintenance base narrow despite organizational ownership and 73 recent commits. CI is complete and read-only at job scope, but all eight actions are unpinned and no security policy is provided.
72%
Total Score
67
100
100
50
One contributor holds 100% of the recent commit share, creating a meaningful continuity risk; organizational ownership provides some backing but no active second contributor is shown.
The repository has 73 commits in the last three months, showing active development, but all were made by one maintainer.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a network-facing server package.
The workflow audit completed cleanly with no untrusted checkout or script-injection findings and job-level permissions, but all eight action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.