The small dependency footprint and included repository tests make the package straightforward to evaluate. Maintenance is currently quiet, and its workflows use unpinned actions, leaving meaningful upkeep and build-integrity caveats.
68%
Total Score
50
83
50
The package is about 870 days old but has only two releases, with one release in the last 12 months and a median interval of about 618 days. This indicates a slow release cadence, though the recent v1.0.0 release provides some evidence of continued publishing.
The repository recorded zero commits and zero active maintainers in the last 3 months. That is a maintenance concern, although the latest release was published recently enough that this does not by itself indicate abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response. The package is small and has repository tests, but no provided signal shows a documented security process to compensate for this gap.
All 8 analyzed action references are unpinned, weakening build reproducibility and increasing exposure to upstream action changes. The audit found no untrusted checkouts, script injection, dangerous triggers, or high-severity findings, which keeps this at a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.