Healthy and suitable to use. The project is actively maintained, has current releases, tests, documentation, and organization backing; the main caveats are install-time scripts and limited security-policy and workflow-permission documentation.
82%
Total Score
100
100
100
50
The package runs post-install and post-update commands, adding installation complexity and requiring consumers to review those scripts before adoption.
No repository security policy was found, leaving vulnerability-reporting expectations less transparent.
The sole analyzed workflow has no top-level token permissions declaration, so its GitHub Actions permissions are less explicit than ideal.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.