Its small scope, MIT licensing, and minimal runtime dependency reduce adoption complexity. Workflow references are all unpinned, and the repository lacks a security policy, leaving avoidable maintenance and build-hygiene concerns.
61%
Total Score
50
100
94
75
The project is owned by an individual rather than an organization, so the single registry maintainer reflects a narrow backing base alongside the inactive repository.
The package has five releases since February 2020, but none in the last 12 months and its latest release was in February 2024; this indicates a meaningful maintenance gap.
There were zero commits and zero active maintainers in the last three months, consistent with the latest release being in February 2024 and raising abandonment concern.
No security policy is present in the repository, leaving vulnerability-reporting expectations undocumented for consumers.
All six analyzed action references are unpinned, and the audit found a high-confidence template-injection issue; because no untrusted trigger or checkout sink is shown, this is workflow hygiene rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.