Its workflows use five unpinned actions, and the repository has no security policy or scanning. Tests, licensing, release notes, and organization backing help, but the release is too stale for a dependable new dependency.
42%
Total Score
50
70
50
The package has only one release, published about 3 years 11 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since its last release.
The linked repository has no security policy and no security scanning tools. This weakens vulnerability-reporting and maintenance transparency, though it is not evidence of a vulnerability itself.
The assessed version is a prerelease beta, and all recent releases are prereleases. That raises compatibility and maturity concerns for a dependency.
All five analyzed action references are unpinned, reducing build reproducibility. The audit found no untrusted checkouts, script injection, or high-confidence findings, which limits the impact to caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.