Clear documentation, tests, release notes, and a security policy make the release easier to evaluate and adopt. Maintenance is concentrated in one contributor, and all 16 workflow actions are unpinned, leaving avoidable continuity and build-integrity concerns.
82%
Total Score
50
100
100
100
One contributor made all 3 recent commits, giving the repository a 100% top-contributor share. The project is user-owned rather than organization-owned, so there is little provided evidence of handoff capacity.
The repository received 3 commits in the last 3 months from one active maintainer. Recent activity is present, but its limited volume reduces evidence of broad maintenance capacity.
All 5 workflows were analyzed successfully and no audit findings or untrusted checkouts were reported; the pull_request_target trigger has no reported sink. However, all 16 action references are unpinned, which is a reproducibility and supply-chain hygiene weakness.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33204 kelvinmo/simplejwt is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.1.0. | 0.0.0 - 1.1.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.