The package is well documented, tested, MIT-licensed, and the repository has recent activity from two contributors. Its small ecosystem and absent security policy leave less assurance than a mature dependency would provide.
78%
Total Score
100
100
83
75
Only one release exists, published 35 days ago, so long-term maintenance and compatibility are not yet demonstrated. Recent repository activity partly offsets the package's limited release history.
The repository has no stars, forks, or watchers, so there is little external adoption evidence. This is a supporting gap only because the project is very young and active maintenance is otherwise visible.
No repository security policy was found, leaving vulnerability-reporting expectations and response procedures unclear.
The assessed version is pre-1.0, which signals that compatibility may still change despite it not being marked as a prerelease.
Both workflows were fully analyzed with no audit findings or untrusted checkout and injection sinks. However, all five action references are unpinned, and one workflow grants top-level write permissions, creating a moderate reproducibility and token-scope hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.