The package is clearly documented and tested, with a small dependency surface and organization backing. Its release and commit activity stopped about 216 days ago, and both workflow actions are unpinned, so ongoing maintenance and build reproducibility remain concerns.
61%
Total Score
50
88
50
Only two releases were published, both on the same day, followed by about 216 days without a newer release. This is a meaningful maintenance concern for a young package, though the project is not deprecated.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap. The repository is still active rather than archived, but current maintenance capacity is unproven.
The repository has no security policy. This is a modest transparency gap, partly offset by the complete workflow audit and the project's small, well-documented structure.
The sole workflow was fully analyzed, uses read-only permissions, and has no reported dangerous findings. However, both of its two action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scedel/schema Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.