Tests, release notes, a license, and a security policy make the project transparent. Its small audience, single-maintainer activity, and workflow audit issue leave less operational margin.
68%
Total Score
50
93
100
One contributor made 100% of the last three months' commits, leaving little visible backup if that maintainer becomes unavailable; the repository is user-owned rather than organization-backed.
The repository had 12 commits in the last 3 months, which shows ongoing work, but all activity came from one active maintainer.
The repository has zero stars and forks and one watcher, so there is little external adoption evidence to offset its young age and concentrated maintenance.
All three workflows were analyzed and no untrusted checkout or script injection was found, but a high-confidence bot-conditions finding says actor context may be spoofable in the Dependabot auto-merge workflow; one of five action references is also unpinned only in the minority case.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.