Clear documentation, tests, and security tooling improve confidence. The small community and missing security policy leave less backup if maintenance stops.
68%
Total Score
75
100
94
50
The package is about 8 years old but has only 3 releases, with a median interval of about 3 years 8 months; one release in the last 12 months shows it is not abandoned, but cadence is slow.
All 7 recent commits came from one contributor, so maintenance depends heavily on a single person; individual ownership does not provide organizational handoff capacity here.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
All four workflows were analyzed with no untrusted checkout or script-injection findings, but every one of 21 action references is unpinned and the audit found a high-confidence unpinned container image.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.