Эталонный справочник почтовых индексов объектов почтовой связи
60%
Total Score
caution
Usable with caveats: the registry release is over five years old despite recent repository activity.
The latest registry release was published about five years ago, with no releases in the last 12 months. The 47-release history shows prior activity, but the published version is stale for a dependency.
All two recent commits came from one contributor, leaving maintenance dependent on a single active person. The project is user-owned rather than organization-backed, so there is no shown handoff capacity to offset this concentration.
No repository security policy was found. That reduces disclosure transparency, although the project does use Dependabot and this is not by itself evidence of unsafe code.
Version v0.3.0 is not a prerelease, but it remains below a stable major version. This is a modest maturity concern rather than a severe release-quality warning.
All 10 analyzed action references are unpinned, and a high-confidence audit found a workflow installing a package outside a lockfile. The workflows have no top-level write permissions and no untrusted checkout or script-injection paths, which limits the risk to hygiene and reproducibility concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sanmai/pindx-client Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.