The repository includes tests, a matching source project, and an MIT license. Its 0.3.0 development status, no commits in three months, absent security policy, and unpinned workflow action limit confidence in ongoing maintenance.
62%
Total Score
75
83
50
Only three releases exist across about 10 months, with the latest release also about 10 months old; this provides limited evidence of sustained delivery.
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have stalled.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that exposes Kubernetes API functionality.
Version 0.3.0 is not a stable major release, and the package documentation says it is still under active development and not ready for production use.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script-injection sink, but its only action reference is unpinned, leaving a modest build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
p8p/client Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.