This is a young but actively maintained and transparently structured release: it has six releases over 96 days, a stable 1.3.1 version, a non-deprecated registry status, a matching source repository, repository tests and releases, security documentation, and no install-time lifecycle scripts. The main concerns are that all 20 recent commits came from one contributor, repository popularity is currently negligible, and workflow permissions are not uniformly least-privilege; these warrant monitoring but do not by themselves make the package unfit to depend on.
72%
Total Score
80
100
94
80
One of three workflows uses pull_request_target, which requires careful review because it can run with elevated repository context; no untrusted checkout or script-injection findings were detected.
The repository is owned by a user account rather than an organization, so the concentrated contributor activity is not offset by visible organizational maintenance backing.
One contributor made all 20 commits in the last three months, creating a material single-maintainer continuity risk for a user-owned repository.
The repository has zero stars and forks and only one watcher; this is weak supporting evidence for adoption and community visibility, though the package is still young.
One workflow has top-level write permissions and another lacks top-level permissions, so workflow authorization is not uniformly explicit or least-privilege.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
k2gl/in-toto-attestation Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.