The organization-backed repository has tests, release notes, a clear license, and a small runtime dependency set. Recent commit inactivity and broadly permitted, unpinned workflows warrant monitoring despite the latest release and active repository state.
78%
Total Score
75
100
94
50
The package has seven releases over roughly 14 months, but only one release in the last 12 months, indicating a slower recent cadence without showing abandonment by itself.
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful maintenance concern even though it was pushed more recently than that window.
The repository has no published security policy, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, not evidence of unsafe code.
All four workflows were analyzed with no audit findings or untrusted checkouts. However, all nine action references are unpinned and three workflows grant top-level write permissions, creating moderate reproducibility and least-privilege hygiene concerns without a demonstrated dangerous sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.