The source remains available and includes tests, a README, and a matching MIT license. Workflow references are unpinned and reusable workflows inherit secrets, increasing maintenance and automation risk.
62%
Total Score
50
100
94
75
The repository is owned by an individual account rather than an organization, so the single registry maintainer represents a relatively thin ownership base.
The latest registry release was over seven years ago, with no releases in the last 12 months; this is a meaningful freshness and maintenance concern.
No commits or active maintainers were recorded in the last three months, which weakens evidence of ongoing development; the non-archived repository partly offsets abandonment risk.
No repository security policy was found. This is a transparency gap, but it is less significant for a small library with limited runtime dependencies.
Both workflows use unpinned actions, and both high-confidence findings report inherited secrets; these create avoidable automation hygiene and credential-scope risks. No untrusted checkout, script injection, or broad top-level write permission was found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.