The package is clearly identified, licensed, tested in the repository, and has a small runtime dependency footprint. Workflow references are unpinned and no security policy is published, leaving avoidable maintenance and supply-chain hygiene gaps.
68%
Total Score
67
100
93
75
The package is only 2 days old with three releases and a median interval of about 1.5 days, so maintenance maturity and long-term stability are not yet established.
All three recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity for handoff but does not show a second active contributor here.
There were three commits in the last 3 months, but activity is sparse relative to the package's early development and does not yet demonstrate sustained maintenance.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no dangerous audit findings or untrusted checkout paths, but both action references are unpinned, weakening reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.