The package is clearly documented, licensed, and recently updated, with a focused dependency set. Its single-contributor maintenance and unpinned workflow actions leave meaningful continuity and build-hygiene concerns.
72%
Total Score
50
100
93
75
Only four releases have been published since November 2023, with no releases in the last 12 months and a median interval of about 314 days. That slow cadence is a maintenance concern, although the repository was recently pushed and version 1.3.0 has release notes.
All recent repository commits came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-backed, so there is no provided organizational compensation.
One commit from one active maintainer was recorded in the last three months, showing current activity but only limited evidence of ongoing maintenance capacity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed without failures and avoid untrusted checkouts, script injection, and top-level write permissions. However, all eight action references are unpinned, and low-confidence cache-poisoning findings indicate build-hygiene weaknesses rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.