The organization has five recent contributors and the package includes release notes, a README, and a license. Two of four workflow actions are unpinned, so reproducibility could be improved by pinning known action versions.
68%
Total Score
100
93
75
The package has only one release, published over four years ago, with no releases in the past year. This raises version freshness and abandonment concerns, although repository activity provides some compensation.
The repository has no security policy, which weakens vulnerability-reporting transparency. The active organization and recent multi-contributor activity partly compensate, keeping this a minor concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, a modest reproducibility concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.