The package has a clear MIT license, a focused dependency footprint, and repository tests. GitHub Actions are not pinned, and no security policy is published.
79%
Total Score
100
100
94
75
Only two releases exist across about 23 months, with roughly 16 months between releases, so the project has a sparse cadence. The latest release is recent and repository activity provides some compensation.
No security policy is published, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence of unsafe code.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.