Documentation, tests, licensing, and recent releases provide a solid maintenance baseline. The project still depends heavily on one contributor, while workflow permissions and unpinned actions add avoidable release risk.
67%
Total Score
50
100
100
75
The source repository is user-owned rather than organization-owned, so the concentrated recent activity does not have visible organizational backing to compensate for the bus-factor concern.
All four recent commits came from one contributor, creating a meaningful single-maintainer continuity risk; the repository is user-owned, so no organizational handoff evidence offsets it.
Four commits were made in the last 3 months, showing current activity, but only one active maintainer contributed them, limiting evidence of durable maintenance capacity.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
All five action references are unpinned, and the audit found a high-confidence bot-conditions issue in a pull_request_target workflow; one workflow also grants top-level write access, adding avoidable automation risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.