The repository has tests, licensing, and security scanning, but recent commit activity is absent and the registry has had no release in over four years. The repository does not identify this package in its name or README, and all three workflow actions are unpinned.
55%
Total Score
50
88
75
The latest registry release was over four years ago, with no releases in the last 12 months. The five-release history shows the package reached a stable version but is not actively releasing.
There were no commits and no active maintainers in the last three months. Combined with the old registry release, this is evidence of weak current maintenance.
The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established by the collected evidence.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but not a severe dependency risk by itself.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three referenced actions are unpinned and the workflow has no top-level permissions block, leaving modest reproducibility and permission-hygiene gaps.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.