The project has organizational backing, a clear README, tests, and release notes for this version. Maintenance depends on one active contributor, and all four workflow actions are unpinned, which weakens resilience and build reproducibility.
76%
Total Score
67
100
100
67
One contributor made all eight commits in the last three months, giving the project a concentrated bus factor. Organization ownership partly offsets handoff risk, but no second active contributor is shown.
The repository recorded eight commits in the last three months, showing recent work rather than collapsed activity. All of that activity came from one active maintainer, which limits resilience.
The repository has no security policy. For a package handling cookies, this is a transparency gap for reporting and handling security issues, though it is not evidence of a security defect.
Both workflows were fully analyzed with no untrusted checkout or script-injection findings, and neither uses broad top-level write permissions. However, all four analyzed actions are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.