The package is clearly documented, tested, and licensed, with a small dependency footprint. Its repository is active and not archived, but operational safeguards are incomplete.
68%
Total Score
83
100
100
67
All 16 recent commits came from one contributor, leaving maintenance highly concentrated; organization ownership provides some handoff capacity but no second active contributor is shown.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations unspecified.
All four workflows were analyzed, but all 12 action references are unpinned, one workflow grants top-level write access, and high-confidence template-injection findings occur in the release workflow. The findings are hygiene concerns because no untrusted trigger or checkout sink was detected, but they still weaken release-workflow assurance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.