Tests and release notes provide useful coverage, while the single runtime dependency keeps the package simple. The README says its usage section is outdated, and both workflow actions are unpinned, reducing documentation and build confidence.
54%
Total Score
50
100
70
50
The package has had 3 releases since June 2021, but none in over 3 years; this is a meaningful maintenance and abandonment concern.
The package includes tests and has release notes for this version, which support maturity, but its README explicitly says the usage section is no longer up to date.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the release gap and indicating inactive maintenance.
The repository has no security policy. This is a transparency gap for a dependency, though the package's small scope and available tests partly reduce the concern.
The workflow was fully analyzed, uses read-only permissions, and has no reported audit findings, but both of its action references are unpinned, leaving the build exposed to moving dependencies.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.