The package is small and clearly documented, with repository tests and a permissive license. Its single-maintainer ownership and lack of a security policy leave limited evidence of broader review.
55%
Total Score
50
100
78
83
All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, which limits the risk but does not remove the automation hygiene concern.
One registry maintainer is consistent with the repository being owned by an individual, but it also indicates a thin maintainer base if the project needs continued support.
Only one release exists, published about 2 years and 8 months ago, with none in the last 12 months. This leaves limited evidence of ongoing maintenance, though a small stable library may need few releases.
There were no commits and no active maintainers in the last three months, and the repository has not changed since January 2024. This is meaningful evidence of stalled maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external validation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.