The repository has tests, a changelog, static analysis, and a clear license, while its organization backing and recent push show ongoing project presence. Workflow dependencies are entirely unpinned, and the absence of a security policy leaves maintenance transparency weaker.
62%
Total Score
75
100
94
50
The package has made no registry release in nearly four years, which raises version freshness and abandonment concerns; the linked repository's recent push provides only partial compensation.
There were no commits from active maintainers in the last three months, despite the repository being pushed recently; this makes current maintenance capacity uncertain.
No repository security policy is present, leaving vulnerability reporting and response expectations undocumented.
All 13 analyzed action references are unpinned, and one medium-confidence archived-action finding was reported; however, the audit found no untrusted checkouts, script injection, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.