The package is backed by an organization, has tests, a clear README, and recent release activity. Its main weaknesses are concentrated recent contribution and unpinned workflow actions, which merit extra review before upgrades.
78%
Total Score
75
100
100
75
All one recent commit came from a single contributor, creating concentration risk; the organization backing provides some ability to hand off maintenance.
There was one commit in the last 3 months, so recent activity exists but is limited for a maintained project.
No repository security policy was found, reducing transparency for vulnerability reporting, although other security tooling is present.
All 3 workflows were analyzed without high- or medium-severity findings and have no untrusted checkouts or script injections. However, all 16 action references are unpinned, creating avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.