The package includes tests, release notes, security scanning, and organization backing. Its small public footprint and missing security policy leave less independent reassurance for long-term adoption.
68%
Total Score
67
100
94
67
The repository recorded no commits and no active maintainers during the last 3 months. This is a meaningful maintenance concern, although the same package released recently and has a long release history.
There were no new or closed issues and no new or merged pull requests during the last month, while 16 issues and 2 pull requests remain open. This indicates limited recent collaboration activity.
The repository has 3 stars, 5 forks, and 10 watchers. This is limited external popularity, but popularity is supporting evidence and does not outweigh the demonstrated release history.
The repository has no security policy. That weakens vulnerability-reporting transparency, though the repository does use automated security scanning.
All three workflows were analyzed without untrusted triggers or script-injection findings, but all 10 action references are unpinned and the build-release workflow uses a floating container image tagged latest. The high-confidence unpinned-image finding is a supply-chain hygiene concern; the low-confidence cache-poisoning finding is weaker evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
justinrainbow/json-schema Version ^5.2 | — | — |
helsingborg-stad/municipio Version * | — | — |
helsingborg-stad/acf-export-manager Version >=1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.