Its small dependency footprint, MIT licensing, tests, and release notes provide useful transparency. The repository is not archived, but security-policy coverage is absent and workflow dependencies are unpinned.
32%
Total Score
50
100
79
83
The registry marks the entire package as abandoned, with no replacement other than the same package name. That is a severe warning for future maintenance and support.
The package has only 5 releases since December 2018 and none in the last 12 months; its latest release was in November 2024. This indicates a slow and currently inactive release cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the latest release received a repository push, current maintenance capacity is not demonstrated.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, though it is not by itself evidence of unsafe code.
The single workflow was fully analyzed with no audit findings or untrusted triggers, but all 3 action references are unpinned. That leaves the build exposed to unexpected action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.