swoft stclib component
61%
Total Score
caution
Usable with caveats: maintenance has gone quiet and all workflow actions are unpinned.
There are only 3 releases, all published within about 1 day, with no later releases during the package's roughly 10-month observed age. That gives limited evidence of sustained release maintenance.
The repository had 0 commits and 0 active maintainers over the last 3 months. With only a single recent release burst, this is weak evidence of ongoing maintenance.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities. This is a transparency and maintenance gap, though not severe on its own.
Both workflows were analyzed successfully with no trigger or injection findings, but all 5 action uses are unpinned. Unpinned actions weaken build reproducibility and make future workflow changes less controlled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.