The release is well documented, tested, licensed, and backed by a matching source repository with security scanning. Its small maintainer base, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
67%
Total Score
50
100
86
50
The package has six releases over about three years, but only one release in the last 12 months. That indicates a slower maintenance pace without showing abandonment by itself.
There were no commits and no active maintainers in the three months measured. Although the repository was pushed in January 2026, the recent quiet period raises maintenance risk.
The repository has no published security policy. This is a transparency gap for a library that processes HTML documents, though security scanning tools provide some compensation.
Version 0.3.1 is a stable, non-prerelease release, but the package remains below 1.0, so compatibility expectations are less mature than for a stable-major project.
The sole workflow was fully analyzed, uses read-only permissions, and has no detected dangerous findings, but all four action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
manychois/cici Version ^0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.