The package has tests, an MIT license, clear documentation, and no install-time scripts. Workflow references are unpinned, and the repository has no security policy, so maintenance and supply-chain hygiene remain limited.
67%
Total Score
50
100
94
75
This is a young package, released only once 47 days ago, so there is little release history to demonstrate sustained maintenance. Its short age partly limits how strongly this should count against it.
The repository recorded zero commits and zero active maintainers in the last three months. Because the package itself is only 47 days old, this is a warning about demonstrated maintenance rather than strong abandonment evidence.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
All five analyzed action references are unpinned, which weakens build reproducibility and action supply-chain hygiene. One workflow has top-level write permissions, but there are no untrusted checkouts, injection findings, or other audited sinks, so this is caution rather than danger.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.