Cookie consent plugin: 100% free, zero cloud dependencies. Helps you comply with GDPR, CCPA/CPRA and ePrivacy, and supports the IAB TCF v2.3 framework (TCF requires a registered CMP ID).
78%
Total Score
healthy
Frequent releases and strong recent activity support adoption, despite 97% of commits coming from one contributor.
The repository owner is an individual rather than an organization, so the very concentrated commit activity is not offset by clear organizational handoff capacity.
Although 7 contributors were active in the last 3 months, the leading contributor made 97.5% of commits. That concentration creates a meaningful continuity risk for a user-owned project.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
All 4 workflows were analyzed successfully; all 13 action references are pinned, permissions are scoped or read-only, and no untrusted checkout or script-injection path was found. One high-confidence low-severity finding reports an ad hoc package installation outside a lockfile, which is a minor hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.