The package is MIT-licensed, tested, and clearly tied to its source repository. Its small audience and absent security policy add modest uncertainty; pin this exact version when adopting it.
73%
Total Score
50
50
The package is 501 days old with four releases, but only one release in the last 12 months, indicating limited recent maintenance activity.
The repository has zero stars and forks and one watcher, so there is little external adoption evidence; this is only a modest concern because popularity is supporting evidence rather than a health verdict.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for users and maintainers.
All three analyzed action references are unpinned, weakening build reproducibility, although both workflows were analyzed cleanly and no dangerous triggers or high-confidence findings were reported.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tourze/wechat-mini-program-appid-contracts Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.