The package is clearly licensed, documented, tested, and linked to a matching organization repository. Its only registry release is over a year old, recent commit activity is absent, and the release workflow has a high-confidence template-injection finding with broad permissions and unpinned actions.
48%
Total Score
63
100
72
63
Only one release exists, published over two years ago, with no releases in the last 12 months. That gives little evidence of sustained registry maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is strong evidence of stalled maintenance.
Both workflows grant top-level write permissions and all five action references are unpinned; the release workflow also has a high-confidence template-injection finding that may expand attacker-controlled input into code. The audit itself was complete, with no untrusted checkout or dangerous trigger detected.
There are 128 open pull requests, five new pull requests in the last month, and no merges in that period. This suggests review or integration backlog despite ongoing contributor interest.
The repository has one star and no forks, indicating very limited adoption. Popularity is supporting evidence rather than a decisive health verdict, so this is a caution rather than a danger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danielmiessler/fabric Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.