The project has strong documentation, tests, release notes, active recent development, and security scanning. Maintenance is concentrated in one recent contributor, and all 16 workflow action references are unpinned.
82%
Total Score
50
100
100
75
The registry namespace and repository are owned by the same individual, confirming coherent ownership but not providing organization-level maintenance redundancy.
One contributor made 100% of the 12 recent commits, creating a meaningful succession and abandonment risk despite the repository's current activity.
The repository recorded 12 commits in the last three months, but all came from one active maintainer; activity is healthy while continuity depends heavily on that person.
No repository security policy was found, leaving vulnerability-reporting guidance less transparent than it could be.
All three workflows were analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 16 action references are unpinned, which weakens build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.