The package has only three releases across about 14 months, and no commits were recorded in the last three months. Tests, a clear README, MIT licensing, and read-only workflow permissions provide useful transparency.
65%
Total Score
50
100
94
75
The repository is owned by an individual account rather than an organization, so the small maintainer base is not offset by visible organizational backing.
Only three releases have been published across about 14 months, with one release in the last 12 months; this suggests a small and potentially slow-moving project.
No commits and no active maintainers were recorded in the last three months, which is a concrete maintenance and abandonment concern.
No repository security policy was found, leaving the process for reporting and handling vulnerabilities unclear.
The workflow uses read-only permissions and has no untrusted checkout or script-injection findings. However, all four action references are unpinned, and the low-confidence cache-poisoning finding is a minor hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.