The repository includes tests, a changelog, a substantial README, and read-only workflow permissions. Its actions are all unpinned and no security policy is published, so maintenance and build hygiene remain less proven.
68%
Total Score
50
100
93
75
The repository is owned by a user account rather than an organization, so the project has no observed organizational backing to offset its lack of history.
This is the first release, published today, so there is no release cadence or history demonstrating sustained maintenance. That is an early-maturity concern rather than evidence of abandonment.
There were no commits from active maintainers in the last three months, but the package was only released today, so this primarily reflects its lack of operating history.
No security policy was found in the repository. This is a transparency gap for a package that processes untrusted JSON, although the available tooling and tests provide some compensation.
The single workflow uses read-only permissions and has no untrusted checkout, injection, or auditor findings. However, all 5 action references are unpinned, leaving the build exposed to reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
softcreatr/jsonpath Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.