The repository has tests, security tooling, a clear license, and no install-time scripts. However, this remains a single-release package from 2019 with no recent commit activity, so maintenance continuity is weak.
48%
Total Score
0
100
79
67
The package has only one release, published in January 2019, with no releases in the last 12 months. That long period without another release is strong evidence of limited ongoing maintenance.
There were zero commits and zero active maintainers in the three months before collection. This directly supports a conclusion of stalled maintenance, despite the repository not being archived.
The repository has no security policy. This is a modest transparency gap, but it is secondary to the much stronger evidence from the release and commit history.
Version 0.1.0 is not a stable major release, although it is not marked prerelease. The immature version combined with the one-release history leaves compatibility and maintenance uncertainty.
The workflow audit completed without findings, dangerous triggers, or untrusted checkouts. All five action references are unpinned, which is a supply-chain hygiene weakness, but the workflow has no observed dangerous sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.