The README, MIT license, and GitHub release provide useful consumer documentation. However, the project has had no commits or active maintainers for nearly four months, and its release workflow leaves all actions unpinned.
52%
Total Score
50
75
50
All three releases appeared within minutes on the first release day, with no later releases across nearly four months. That short, burst-only history provides little evidence of sustained maintenance.
The repository recorded no commits and no active maintainers in the past three months, despite being only about four months old. This raises abandonment risk for a young extension.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear for an extension that handles database access. No provided signal compensates for that transparency gap.
All three analyzed action references are unpinned, and the release workflow grants top-level write permissions. The high-confidence template-injection findings are hygiene concerns here because no pull_request_target or workflow_run trigger was reported.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.