The source repository has tests, a changelog, dependency scanning, and a recent push despite no registry release in over a year. Workflow permissions and inherited secrets need tightening, while the package itself has a small, focused dependency surface.
68%
Total Score
75
100
94
67
The package has seven releases over roughly three years, but there have been no registry releases in the last 12 months; this indicates slowed release maintenance.
There were no commits and no active maintainers in the measured last three months, which is a meaningful maintenance warning, although the repository has a more recent recorded push outside that window.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a modest transparency gap for a dependency project.
All six workflows were analyzed, but all nine action references are unpinned, three workflows grant top-level write permissions, and high-confidence secrets-inherit findings pass credentials to reusable workflows. No untrusted checkouts or script-injection findings were found, which limits the severity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.