The source is small but structured, with repository tests, a clear MIT license, and automated dependency scanning. Its workflow leaves all 11 actions unpinned, weakening build reproducibility.
62%
Total Score
50
83
50
The package has only three releases and none in the last 12 months, despite a median interval of about 22 days earlier; this is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers over the last 3 months, indicating a recent pause in observed development.
No security policy is provided, leaving vulnerability-reporting expectations undocumented; this is a transparency gap but not a severe dependency risk by itself.
The current v0.1.2 release is not a stable major version, so its API may still change; it is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 11 action references are unpinned, weakening supply-chain reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.