Documentation is strong, with repository tests, release notes, a security policy, and a clear license. CI uses security tooling, but all 14 action references are unpinned.
70%
Total Score
67
100
92
83
There is one registry publisher, Stanislas Poisson, and the repository is user-owned rather than organization-backed. This leaves a thin visible maintainer base, although the release activity shows active work by that maintainer.
This is the first release, published 0 days ago, so there is no demonstrated release track record yet. That limits confidence in long-term maintenance but is not evidence of abandonment by itself.
The repository records 0 commits and 0 active maintainers in the last 3 months, which is a maintenance concern for a dependency. The package is newly released, so this may reflect its age rather than a collapse in activity.
Both workflows were analyzed successfully with no dangerous triggers or audit findings. However, all 14 action references are unpinned, and one workflow grants top-level write permissions, creating avoidable build-integrity and token-scope weaknesses.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.