Tests, a clear README, a small dependency footprint, and static analysis improve confidence. The single maintainer and broad, unpinned workflow references leave maintenance and build hygiene concerns.
61%
Total Score
50
100
94
75
One registry maintainer is a modest continuity risk for a user-owned project, although the repository is clearly linked and the package is not deprecated.
This is a single-release package, with no releases in the last 12 months and the latest release about 14 months ago. That limits evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that may have stalled after its initial release.
All four action references are unpinned, and the workflow has top-level write permissions. The only audit finding is low-confidence cache-poisoning hygiene, so this lowers confidence modestly rather than making the package unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.