The project includes tests, clear licensing, and recent releases, with no install-time scripts or deprecation. Workflow actions are all unpinned, and recent commits come entirely from one maintainer; the missing security policy adds a smaller transparency gap.
68%
Total Score
67
100
100
83
The repository is owned by the same individual namespace as the package, providing direct ownership alignment but no organizational backing to offset the single-maintainer concentration.
All ten recent commits came from one contributor, leaving maintenance highly dependent on a single person and reducing resilience if that person stops contributing.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 10 action references are unpinned, so workflow dependencies can change unexpectedly.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.