Clear documentation, a permissive license, repository tests, and release notes support day-to-day use. The project has enough structure to adopt, though its current maintenance depth and automation hygiene merit closer scrutiny.
64%
Total Score
67
100
100
75
One contributor supplied all commits in the last 3 months. Organization backing reduces handoff risk, but no second recently active contributor is shown.
Only 1 commit was recorded in the last 3 months, indicating a thin recent maintenance cadence despite the recent release history.
All five analyzed action references are unpinned, and the auditor found a high-confidence, high-severity bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target workflow had no untrusted checkout or script-injection sink, limiting the immediate severity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.