A small dependency set, clear licensing, repository tests, and release notes support straightforward adoption. The workflows are fully unpinned and install-time scripts add avoidable maintenance and supply-chain exposure.
61%
Total Score
50
100
90
67
The package declares post-install-cmd and post-update-cmd scripts, so dependency installation and updates execute package-defined lifecycle behavior. This is a modest supply-chain and maintenance concern, though it is not evidence of maliciousness by itself.
This is the only release, published 838 days ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance for a package a developer may need to depend on over time.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since its only release. The repository is not archived, but there is no recent activity to offset the inactivity concern.
All 4 workflows were analyzed successfully with no high- or medium-severity findings and no untrusted checkout or script-injection paths. However, all 5 action references are unpinned, leaving workflow builds exposed to moving action versions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.