The repository is active enough to remain available, matches the package, and includes tests, a changelog, and Dependabot scanning. Registry history is thin, with no new release for about eight years, while all six workflow actions are unpinned. Pin this version only if its older API and maintenance cadence fit your project.
60%
Total Score
75
100
81
67
This package has only one release, published about eight years ago, with no releases in the last 12 months. That is a meaningful maintenance and freshness concern despite the package not being deprecated.
There were no commits and no active maintainers in the last three months. This weakens evidence of ongoing maintenance, even though the repository has a recent push timestamp.
No security policy is present. This is a minor transparency gap for a small package, but it does not by itself indicate abandonment or unsafe behavior.
Version 0.1.0 is not a stable major release, although it is not marked as a prerelease. The early version increases compatibility uncertainty for consumers.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all six action references are unpinned, leaving workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.