Its MIT license, focused dependencies, README, repository tests, and release notes provide useful transparency. The GitHub Actions use four unpinned actions and the repository has no security policy, so maintenance hygiene remains limited.
67%
Total Score
50
100
92
67
The package has made no release in nearly two years despite six releases since October 2022, which lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, indicating currently inactive development.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Both workflows were fully analyzed with no dangerous sinks or audit findings, but all four referenced actions are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.