Recent releases, repository tests, and security scanning provide useful maintenance evidence. However, all recent commits came from one contributor, and the linked repository does not clearly identify this package; its workflow also leaves all 15 action references unpinned.
68%
Total Score
67
100
94
67
One contributor made all 4 commits in the last 3 months, giving the project a top-contributor share of 100%. Organization ownership offers some handoff potential, but no second active contributor is shown.
Four commits were made in the last 3 months, showing current activity, but that activity is concentrated in a very small maintenance base.
The repository name does not match the package name, and no README package mention was found. That leaves uncertainty about whether the linked source repository is specifically for this package rather than a related or reused project.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, though it is not evidence of abandonment by itself.
The single workflow was fully analyzed, uses read-only permissions, and has no detected injection or high-severity findings. However, all 15 action references are unpinned, leaving the workflow exposed to moving action contents.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lesname/value-object Version ^0.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.