MIT licensing, a matching repository, and repository tests improve transparency. The workflow grants top-level write access, though the audit found no untrusted checkout or script injection. Pin this version only if your project accepts an immature API.
68%
Total Score
100
100
83
67
This is the first release, published within the last day, so there is no release track record or demonstrated maintenance cadence yet.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The package is at pre-1.0 version v0.1.0, which signals that its API may still change even though it is not marked as a prerelease.
The single workflow uses top-level write permissions, which is broader than necessary, but the audit found no untrusted checkout, script injection, or other findings, so this is a mild hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dragonmantank/cron-expression Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.