The repository is minimal, with a working test layout and a clear MIT license. Its only release was over two years ago, there has been no recent commit activity, and all six workflow actions are unpinned.
45%
Total Score
50
50
50
This is the package's only release, published over two years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the one-release history, this indicates substantial abandonment risk.
The package includes tests and a README, but the README is only 14 characters and provides no useful consumer guidance. The missing changelog is normal packaging practice and is not a concern by itself.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. The package's small size and test tooling partly limit the significance, but do not remove the gap.
All three workflows were analyzed successfully and showed no dangerous triggers, sinks, or audit findings. However, all six action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.