Clear documentation, tests, release notes, and a matching organization-backed repository improve confidence in the package. The absent security policy and unpinned workflow actions add smaller maintenance and build-hygiene concerns.
58%
Total Score
75
100
94
75
The package has 14 releases since June 2021, but none in the last 12 months and its latest release was about 2 years and 9 months ago. This is a meaningful sign of stalled maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with the last push being about 2 years and 9 months ago. This materially raises the risk of stale maintenance.
The repository has no security policy. This is a modest transparency gap for reporting vulnerabilities, but it does not by itself show that the package is unsafe to depend on.
All four workflows were analyzed with no dangerous triggers, sinks, or audit findings, but all 13 action references are unpinned. That leaves avoidable build-integrity risk, though no high-confidence workflow vulnerability was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pheature/toggle-model Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.