Tests, documentation, and security tooling support adoption. Maintenance has been quiet for three months, and the repository has no security policy; pin this exact version and review its unpinned CI actions.
70%
Total Score
75
100
94
50
The package has four releases over about three years and one release in the past 10 months. This is a modest cadence, but it is not evidence of abandonment on its own.
The repository recorded no commits and no active maintainers in the past three months. Although it was pushed about two months ago, the measured recent activity is still quiet and lowers confidence in ongoing maintenance.
The repository has no security policy. For a maintained library this is a transparency gap, even though security scanning tools are present.
All 28 analyzed action references are unpinned, so workflow dependencies can change without a reviewed version update. The audit found no untrusted checkout, script injection, or high-severity issue, which keeps this as a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
myth/collection Version dev-develop | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.