The project has a clear license, repository tests, and no install-time scripts. One contributor made all recent commits, while every analyzed action reference is unpinned and no security policy is present.
73%
Total Score
63
100
100
75
The registry and repository are owned by the same individual, so the package identity is consistent, but there is no organization backing to offset the concentrated maintainer base.
One contributor made 100% of the 33 recent commits. The active cadence is reassuring, but this concentration creates a real continuity risk for a user-owned project.
There were 33 commits in the last three months, demonstrating current development activity, although all were made by one active maintainer.
The repository has no security policy. This is a modest transparency gap for a maintained library, despite the presence of automated security scanning.
All eight workflows were analyzed without high- or medium-severity findings and no untrusted checkout or script-injection paths were found. However, all 12 action references are unpinned and four workflows grant top-level write permissions, creating workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.