The package has tests, a clear MIT license, and only two runtime dependencies. Its single-maintainer project has had no commits or releases for about 18 months, while all 15 workflow actions are unpinned.
57%
Total Score
50
100
92
50
Only one registry account has publish access, leaving little publishing redundancy. This is a real resilience concern for a user-owned project without evidence of broader backing.
The package has had no releases in the last 12 months, and its latest release was published about 18 months ago. Earlier releases show project history, but the current release cadence raises maintenance concerns.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than evidence of an active security problem.
The workflow audit was complete and found no dangerous triggers, untrusted checkouts, or injection issues. However, all 15 referenced actions are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.