The package is well documented, licensed, tested, and has a recent repository push. Workflow references are unpinned and no security policy is published, which weakens transparency.
68%
Total Score
50
94
50
The package has 77 releases since May 2017, but none in the last 12 months. That long release gap lowers confidence in ongoing maintenance despite its historically regular cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although it was pushed within the last year, the current inactivity is a maintenance concern.
The repository has no published security policy. This is a transparency gap, though it is less serious because automated security scanning is present.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, or audit findings. However, all four action references are unpinned, leaving their exact versions uncontrolled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
toolkit/pflag Version ~2.0 | — | — |
toolkit/fsutil Version ~2.0 | — | — |
toolkit/stdlib Version ^2.0 | — | — |
toolkit/cli-utils Version ~2.0 | — | — |
toolkit/sys-utils Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.