The MIT license, focused dependency set, tests in the repository, and security policy improve transparency. The long period without releases or commits leaves maintenance and future compatibility uncertain.
43%
Total Score
0
100
71
100
The package has had three releases, but its latest release was on January 24, 2022, with no releases in the last 12 months. This long release gap is a substantial maintenance concern.
There were zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence that development is inactive.
The linked repository is not archived, which is a positive sign, but its last push was on October 9, 2023 and does not offset the more recent inactivity shown elsewhere.
Version 0.1.2 is not a stable-major release, which limits maturity evidence, although it is not marked as a prerelease.
All four workflows were analyzed, but all eight action references are unpinned; the audit also found high-confidence bot-condition and unpinned-container-image issues. The pull_request_target workflow has no untrusted checkout or script-injection sink, so these are workflow hygiene risks rather than a severe package-health failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.