The source includes a full test suite, matching README, and release notes for this version. Its small dependency surface and MIT license reduce adoption friction; pin workflow actions and watch for renewed maintenance.
60%
Total Score
50
100
92
50
A post-install-cmd script runs during installation, adding execution behavior that deserves review even though this signal alone does not establish a severe risk.
The package has 28 releases since January 2017, but none in the last 12 months and the latest release was nearly two years ago. This is a meaningful maintenance concern despite its established history.
The repository recorded zero commits and zero active maintainers in the last three months. The repository was pushed more recently and this release has notes, but current activity remains weak.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities. This is a modest concern rather than evidence of abandonment on its own.
All workflows were analyzed with no reported audit findings or untrusted-trigger sinks, but both action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions are a hygiene weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.