Clear licensing, documentation, and project tooling make the package easy to evaluate and integrate. The unpinned workflow actions and absent security policy add maintenance hygiene concerns.
58%
Total Score
67
100
94
50
The latest registry release was over four years ago, with no releases in the last 12 months; this is a meaningful sign of limited ongoing maintenance.
There were no commits from active maintainers in the last three months, which weakens evidence of current maintenance even though the repository is not archived.
There are nine open pull requests but no new or closed issues or merged pull requests in the last month, consistent with limited active maintenance.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear; this is a modest transparency gap for a small testing library.
All 20 analyzed action references are unpinned, and the audit found one high-confidence medium-severity use of an archived action; there were no untrusted checkouts or script-injection findings.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.