The package has a clear MIT license, tests in its repository, and only one runtime dependency. Its stable 1.1.0 API may still suit tightly controlled use, but ownership is thin and ongoing care is uncertain.
46%
Total Score
33
100
83
75
Only two releases were published, both in October 2022, with no release in nearly four years. This is a substantial abandonment concern for a dependency, despite the stable major version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
The audit found high-confidence bot-condition and unpinned-container-image issues, and all eight action references are unpinned. A pull_request_target workflow also has top-level write permissions, increasing workflow supply-chain exposure even without an untrusted checkout or script injection.
The repository is owned by an individual account rather than an organization, so the single registry maintainer reflects a thin backing structure and leaves limited visible continuity if that maintainer stops work.
There are no open issues and two open pull requests, with no issue or pull-request activity in the last month. The quiet issue tracker is not independently harmful, but the unmerged pull requests offer no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.