It has a clear MIT license, strong repository tests, recent release notes, and active releases. Keep in mind the project has little contributor redundancy and one workflow uses an archived action.
68%
Total Score
50
100
100
50
Only one account has registry publish access. Because the repository is user-owned rather than organization-backed, this leaves limited publishing redundancy.
All six recent commits came from one contributor, so maintenance depends heavily on a single person without evidence of an active handoff path.
Six commits were made in the last three months by one active maintainer, showing recent work but limited maintenance depth.
No repository security policy was found, which weakens the documented process for reporting and handling vulnerabilities.
All six workflows were analyzed successfully with no untrusted checkout or script-injection findings, but 19 of 21 action references are unpinned and one medium-confidence archived-action finding was reported; one workflow also grants top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
marjovanlier/stringmanipulation Version ^2.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.