Security policy coverage is missing, and recent repository activity has been quiet despite a current release. The project remains licensed, tested in its repository, non-archived, and supported by automated dependency updates.
68%
Total Score
67
100
100
75
The repository recorded zero commits and zero active maintainers in the last three months. A recent release provides some compensation, but the quiet development window is a real maintenance concern.
No issues were opened or closed in the last month, and no pull requests were merged, while 40 issues and 16 pull requests remain open. This suggests limited recent project throughput.
No repository security policy was found. For a library intended for application integration, this reduces transparency around vulnerability reporting and response.
All three workflows were analyzed without untrusted triggers or script injection, but the audit found a high-confidence unpinned container image and all 16 action references are unpinned. This is a workflow hygiene concern, not a severe dependency-health failure on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.