The source is recent and releases arrive about every four weeks. The package is licensed, has repository tests and a changelog, and uses no install-time scripts. Pin the two workflow actions before relying on automated releases.
74%
Total Score
67
100
75
All recent commits come from one contributor, creating concentration risk. Organization ownership provides some ability to hand off maintenance, but no second recent contributor is shown.
Only one commit was recorded in the last three months, by one active maintainer. The recent release and broader release cadence help, but this is a genuine sign of limited current maintenance activity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not evidence of unsafe code by itself.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or reported audit findings. However, both analyzed action references are unpinned, leaving automated builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.