The small package is easy to inspect, has tests, and uses no install-time scripts. MIT licensing, a readme, and a focused dependency set make adoption straightforward, but future fixes may be slow.
58%
Total Score
50
100
90
75
The package has existed for about 3 years 10 months, but its latest release was on November 1, 2022, with no releases in the last 12 months. This indicates a largely inactive release process, though the four-release history shows it was published deliberately.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with no visible maintenance since November 2022. That raises the risk that compatibility fixes will not arrive promptly.
The repository has no security policy. For a small package this is a transparency gap rather than evidence of unsafe code, but it gives maintainers and users no documented vulnerability-reporting path.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts, injection findings, or high-confidence audit issues. However, both action references are unpinned, leaving a modest build-reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.