The package is clearly identified by its repository and includes a license, README, tests in the source project, security documentation, and automated scanning. Its negligible repository adoption and heavily unpinned workflow actions add uncertainty around long-term support and build reproducibility.
44%
Total Score
50
100
83
83
This package has only one release, published about 2 years and 5 months ago, with no releases in the last 12 months. That is strong evidence of limited maintenance for a dependency release.
The linked repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the stale release history and raising abandonment risk.
The repository has 0 stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counts provide no visible community support to offset the maintenance concerns.
All three workflows were analyzed, use read-only permissions, and had no audit findings, but 17 of 18 action references are unpinned. That weakens build reproducibility without indicating a severe workflow risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.