The package is deliberately small, with a clear README, repository tests, and no install-time scripts. Resolve the license mismatch and pin the three workflow actions before relying on it broadly; no commits in three months also limits maintenance evidence.
72%
Total Score
50
100
83
100
The manifest declares MIT, but the artifact and repository license files are detected as CC0-1.0. A license is present, but the mismatch creates meaningful clarity risk for consumers.
The package has two releases, both published within roughly 23 minutes, and has existed for 105 days. This shows an initial release sequence but provides little long-term maintenance history.
There were no commits and no active maintainers in the last three months. For a package only 105 days old, this limits evidence of ongoing maintenance, although the small scope may reduce the need for frequent changes.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three referenced actions are unpinned. That is a workflow hygiene and reproducibility concern, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.