The package has clear documentation, tests in the repository, release notes, and recent development. Its automation and single-contributor structure leave maintenance and publishing risks that deserve attention.
67%
Total Score
63
100
100
75
Only one registry account has publish access. The repository is also owned by a personal user account, so there is no organization backing shown to compensate for the narrow maintainer base.
The repository owner is an individual user rather than an organization, so the project shows limited institutional backing. Recent releases and commits provide some compensation but do not remove the single-owner risk.
One contributor made all 12 commits in the last 3 months, creating a fragile maintenance handoff if that contributor becomes unavailable. The recent activity is a partial compensating signal, but not enough to remove the concentration risk.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap for a dependency intended for integration into applications.
All 11 action references are unpinned, and three workflows grant top-level write permissions; these are workflow hygiene weaknesses. The audit also found a high-confidence bot-condition issue, although no untrusted checkout or script-injection sink was detected, so this is caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.