The repository shows no commits in the last three months, and all four workflow action references are unpinned. The MIT license, tests, release notes, focused dependency set, and active repository backing provide useful transparency.
61%
Total Score
100
100
94
75
The package has had no release in nearly four years: its latest release was July 17, 2022, despite a history of 10 releases since 2019. This materially raises abandonment and compatibility risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. CodeQL provides some compensation but does not replace a published response process.
All three workflows were analyzed successfully with no dangerous triggers or audit findings, but all four action references are unpinned. That leaves avoidable workflow supply-chain drift risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.