The package is small and focused, with a BSD license, tests, and release notes for this version. Its security documentation is absent, and the workflow needs stronger dependency pinning; keep maintenance activity under review.
63%
Total Score
50
100
93
50
The package has four releases over about two years, but only one release in the last 12 months. That indicates a relatively quiet release cadence, although the recent release shows the project is not abandoned.
The repository recorded no commits and no active maintainers during the last three months. The repository was pushed around the assessed release, which partly offsets but does not remove the sign of limited ongoing maintenance.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities. This is a documentation gap rather than evidence of an unsafe release.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, and it does not grant top-level write permissions. However, all four action references are unpinned, leaving the build exposed to unexpected action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.