The package has clear documentation, MIT licensing, release notes, tests in the repository, and a clean workflow audit. Recent commit activity is absent, releases are infrequent, and all 10 workflow actions are unpinned, while the missing security policy reduces transparency.
75%
Total Score
83
100
94
75
The package has existed for about 9 years and released version 5.2.0 recently, but only one release occurred in the last 12 months and the median interval is about 10 months, indicating a slow maintenance cadence.
There were zero commits and zero active maintainers in the last 3 months. The recent push and release provide some counterweight, but the current development inactivity still raises abandonment concern.
The repository has no security policy. This is a transparency gap for a library that may be deployed in web applications, although the available tooling and clean workflow audit partly offset it.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 10 action references are unpinned, which leaves a reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.