It includes a clear README, tests, MIT licensing, and static analysis. Maintenance has stopped since March 2025, with one maintainer and unpinned workflow actions adding avoidable risk.
62%
Total Score
50
90
50
One registry maintainer is a thin operational base for a library, although the repository is owned by the same individual and the package appears consistently tied to that project.
The package has had only one release, published in March 2025, with no releases in the following 12 months. That limits evidence of ongoing maintenance, though a stable 1.0.0 release can still be suitable for a small library.
The repository recorded no commits and no active maintainers during the last three months, consistent with the long gap since its only release. This is a meaningful maintenance and abandonment concern.
The repository has no published security policy, which reduces transparency for vulnerability reporting. This is a modest gap rather than evidence that the package is unsafe.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive permissions, but all 4 of 4 action references are unpinned. That leaves the build exposed to moving action revisions and is a hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.