It has an MIT license, README, changelog, and no install-time scripts. The source is correctly linked and not archived, but the release and repository activity indicate abandonment risk; adopting it is a liability.
38%
Total Score
50
81
67
The package has only one release, published about 4 years 11 months ago, with no releases in the last 12 months. This strongly suggests the package is no longer maintained.
The repository has no new issues, closed issues, pull requests, or merged pull requests in the last month. This is consistent with the long period without releases, though zero issue activity alone is not decisive.
The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of an active user or contributor community. Popularity is supporting evidence, but these values reinforce the maintenance concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package that may be used in production applications.
The single workflow was fully analyzed with no reported audit findings or untrusted execution paths. However, both of its action references are unpinned, leaving the build exposed to reference changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.