The repository matches the package and includes tests, release notes, and a substantial README. Its workflow has no detected dangerous findings, but all three actions are unpinned and the repository has no security policy. The small project footprint limits confidence in long-term support.
61%
Total Score
50
100
80
75
Only two releases have been published, with one release in the last 12 months and a median interval of about 334 days. This suggests a small, infrequently updated project, though the package may be intentionally stable.
The repository had zero commits and zero active maintainers in the last three months, adding evidence of limited recent maintenance. The release from about nine months earlier provides some compensating activity but does not remove the concern.
The repository has 1 star, 1 fork, and no watchers, indicating a very small user and contributor footprint. Popularity is only supporting evidence, but this provides little independent confidence in sustained maintenance.
The repository has no published security policy. For a library that handles reCAPTCHA verification, this is a transparency and vulnerability-reporting gap.
The sole workflow was fully analyzed with no dangerous audit findings, but all 3 action references are unpinned. That weakens build reproducibility and supply-chain hygiene without showing an active unsafe workflow.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.