The repository includes tests, a changelog, a security policy, and static analysis. Workflow image pinning is weak, and the small project footprint offers little resilience if maintenance is needed.
40%
Total Score
50
88
100
Only two releases exist, with the latest published about five years ago and none in the last 12 months. This is strong evidence of stalled maintenance despite the package having an established release history.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release gap and indicating a high abandonment risk.
There were no new or closed issues or pull requests in the last month, while three issues and two pull requests remain open. This provides no evidence of active issue resolution.
All 13 analyzed action references are unpinned, and a high-confidence audit found an unpinned container image. The workflows have no dangerous triggers or broad top-level write permissions, so this is a hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tipoff/support Version ^1.8.8 | — | — |
tipoff/bookings Version ^2.2.1 | — | — |
tipoff/checkout Version ^2.5.2 | — | — |
tipoff/authorization Version ^2.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.