Maintenance is light, with only three releases over about 20 months and no commits in the last three months. The project has clear documentation, tests in the repository, licensing, and release notes, but its automation uses unpinned actions and broad write permissions.
62%
Total Score
75
100
86
50
Only three releases have appeared across about 20 months, with one release in the last 12 months and a typical gap of about 230 days. This indicates a small, slow-moving project rather than an actively evolving dependency.
There were no commits and no active maintainers in the last three months. Although a recent release exists, the lack of recent source activity is a meaningful maintenance warning.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show that the package is unsafe.
Version 0.0.3 is not a stable major release, so the public API may still change. There is no prerelease labeling, which provides limited additional warning but does not offset the early-stage versioning.
All 12 analyzed action references are unpinned, and three workflows grant top-level write access. The audit also found a high-confidence bot-condition issue in a pull-request-target workflow; with no untrusted checkout or script injection, this is a serious hygiene concern but not an automatic disqualifier.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.