The project is young but actively developed, with two contributors and one carrying most commits. Missing security guidance and unpinned workflow actions reduce transparency and build hygiene.
78%
Total Score
83
92
50
The package is only 43 days old, so its long-term maintenance record is limited, but six releases and recent activity show active early development.
Two contributors are active, but one accounts for 80% of recent commits, leaving maintenance somewhat dependent on a single contributor.
The repository has no security policy, which weakens vulnerability-reporting transparency, though this is a hygiene gap rather than evidence of abandonment.
All three workflows were analyzed without injection or high-severity findings, and none grants top-level write access. However, all three action references are unpinned, reducing build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
liberusoftware/sessions-devices Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.