Documentation, tests, release notes, and a security policy make the package straightforward to evaluate and maintain. Dependabot and read-only workflow permissions help, though all recent commits come from one contributor and workflow actions are not pinned.
78%
Total Score
75
100
100
100
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not visibly offset by broader organizational backing.
One contributor made all nine commits in the last three months, concentrating maintenance knowledge and creating a real continuity risk for a user-owned project.
All three workflows were analyzed successfully, use read-only permissions, and had no reported audit findings or untrusted checkout sinks. However, all seven action references are unpinned, leaving the workflow supply chain less reproducible.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.