The repository is backed by an organization, includes tests, release notes, and dependabot, with no deprecation or archive status. Recent commit activity is currently absent, and all 13 workflow actions are unpinned, so maintenance and build-integrity risk remain.
72%
Total Score
75
100
94
75
The package is mature, with releases since 2017, but only four releases overall and a median interval of about 3.8 years indicate a slow release cadence.
The repository has zero commits and zero active maintainers in the past three months. With only one release in the past year, this indicates currently paused maintenance rather than an actively evolving project.
There are no open issues or pull requests and no issue or pull-request activity in the past month. This is neutral for a small stable module but provides little evidence of active support.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though the small dependency profile and organization backing partly reduce its significance.
All three workflows were analyzed successfully with no trigger, injection, or auditor findings, and none grants top-level write access. However, all 13 action references are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.