The package includes tests, a substantial README, release notes, and security scanning. Its workflow is fully analyzed with no dangerous findings, but dependency references are unpinned and the repository has no security policy.
65%
Total Score
75
100
88
67
The package is young at 62 days with two releases about 31 days apart, so its longer-term maintenance record is not yet established.
All 22 recent commits came from one contributor, leaving maintenance highly concentrated and creating a meaningful continuity risk.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that this repository is the package's source.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed with no dangerous audit findings and no untrusted checkout or script-injection paths. However, both action references are unpinned, so their exact revisions are not reproducibly controlled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.