Strong documentation, testing, licensing, and security coverage make the project easy to evaluate. Recent repository activity is thin and entirely concentrated in one maintainer, while all seven workflow actions are unpinned.
78%
Total Score
50
94
100
All recent commits come from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-backed, so there is no shown handoff capacity to offset that concentration.
Only one commit was recorded in the last three months, with one active maintainer; this indicates thin recent maintenance even though the project is not abandoned.
The assessed release is a stable, non-prerelease major version with no recent prerelease share. The reported latest version being v1.0.1 conflicts with the assessed v1.1.0 and slightly reduces confidence in the metadata.
All three workflows were analyzed successfully, use read-only permissions, and have no reported audit findings or untrusted checkout sinks. However, all seven action references are unpinned, leaving avoidable dependency-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.