The package is licensed, documented, and backed by repository tests, release notes, security scanning, and minimal runtime dependencies. Maintenance has been quiet for three months, while all six workflow actions are unpinned and no security policy is provided.
72%
Total Score
75
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent release history provides some countervailing evidence.
The repository has zero stars, forks, and watchers, so there is little visible community adoption or external validation. Popularity is supporting evidence only and does not outweigh the package's other healthy signals.
No repository security policy is provided, leaving vulnerability-reporting guidance unclear. This is a modest transparency gap rather than a direct dependency risk.
The single workflow was fully analyzed, has read-only permissions, and has no detected dangerous sinks or audit findings. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.