Healthy and suitable to use, with one maintenance caveat: the project has a long release history, a current release, strong organizational backing, and good repository hygiene, but only one commit from one contributor in the last three months.
82%
Total Score
63
100
100
90
All one recent commit came from a single contributor. This concentration is a weakness, although organization ownership provides some capacity to hand maintenance off.
Only one commit was recorded in the last three months, from one active maintainer, which is a meaningful sign of slowed recent development despite the current release and broader project backing.
The repository has 82 open issues, with no issues closed in the last month, but it also merged five pull requests during that period; this suggests some ongoing work alongside backlog pressure.
Three workflows do not declare top-level token permissions, and one declares top-level write access; this is a workflow-hardening gap, though no dangerous workflow patterns were detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-49282 microsoft/microsoft-graph is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.16.0 - 1.109.1 and 2.0.0-RC1 - 2.0.1. | 1.16.0 - 1.109.12.0.0-RC1 - 2.0.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
microsoft/microsoft-graph-core Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.