The package is documented and tested, with a recent release and a clean repository link. Its small maintainer base and unpinned workflow actions leave more maintenance and build-integrity risk than ideal.
68%
Total Score
50
100
67
Only one registry account has publish access. Because the repository is user-owned rather than organization-owned, this leaves limited publishing continuity if that maintainer becomes unavailable.
One contributor made all recent commits, so maintenance depends entirely on a single person with no demonstrated handoff capacity.
Only one commit was recorded in the last 3 months, indicating limited recent development activity, although the latest release was published during that period.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
The workflow uses read-only permissions and has no injection or high-severity findings, but both analyzed actions are unpinned. That weakens build reproducibility and leaves action resolution dependent on mutable references.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.