The package is licensed, documented, tested in its repository, and backed by an organization. Its maintenance record is thin, while workflow checks show a high-confidence bot-condition issue and all 10 actions are unpinned.
57%
Total Score
83
88
75
There has been only one release, published about 14 months ago, with no releases in the last 12 months. That leaves little evidence of continued release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, this is meaningful evidence of stalled maintenance.
The repository is not archived, so it remains open to maintenance. Its last push was about 14 months ago, consistent with the separate evidence of limited recent activity.
No security policy was found in the repository. This is a transparency and incident-handling gap, though it is not by itself evidence that the package is unsafe.
The audit analyzed all four workflows, but all 10 action references are unpinned, and one high-confidence bot-conditions finding may allow actor context to be spoofed. Three workflows also grant top-level write permissions; with no untrusted checkout or script-injection findings, this remains a workflow-hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.