Tests, release notes, and a matching MIT license improve transparency. Organization ownership supports handoff, but the project has no security policy and all workflow actions are unpinned.
62%
Total Score
83
100
83
67
The package is brand new, with only two releases and less than 12 hours between the first and latest release. This provides too little history to establish durable maintenance.
One contributor made all seven commits in the last three months. This concentrated maintenance base increases continuity risk, although organization ownership provides some potential handoff capacity.
The repository has no security policy. For a native extension handling network and browser-fingerprint functionality, this is a meaningful transparency gap.
Version v0.1.2 is not a prerelease, but the 0.x major version indicates an early-stage API and limited maturity.
The audit covered both workflows without failures and found no untrusted checkouts or script injection, but all 14 action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene and supply-chain exposure concerns, not a severe risk on their own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.