a class collection for different device types
68%
Total Score
caution
Usable with caveats: all recent commits come from one contributor and every workflow action is unpinned.
The repository is owned by an individual rather than an organization, so the concentrated recent activity has no visible organizational handoff buffer.
One contributor made all two commits in the last three months, leaving maintenance dependent on a single active person.
There were two commits in the last three months, so activity is present but modest and concentrated in a small maintenance window.
No repository security policy was found. This is a transparency gap for reporting and handling vulnerabilities, though active security scanning partly compensates.
All 12 analyzed action references are unpinned and four workflows grant top-level write permissions, creating workflow-hygiene concerns. However, all workflows were analyzed, no high-confidence findings were reported, and no untrusted checkout or script-injection paths were found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.