The package has a small dependency surface, clear documentation, tests, release notes, and an Apache-2.0 license. Its single-maintainer project has been inactive for nearly three years, and all three workflow actions are unpinned.
58%
Total Score
50
90
75
One registry maintainer creates a thin publishing base and a higher bus-factor risk, although the linked repository is owned by the same individual and the package is small.
The package has only four releases and none in nearly three years, which raises maintenance and abandonment concerns despite its relatively short release intervals at the start.
The repository shows no commits or active maintainers in the last three months, consistent with inactivity since the November 2023 release and reducing confidence in ongoing maintenance.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear; the package's small scope does not fully compensate for that transparency gap.
The workflow is fully analyzed, uses read-only permissions, and has no reported dangerous findings, but all three action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.