The package has clear documentation, tests, a matching repository, and a permissive license. Its single-release history and absent recent commit activity leave maintenance maturity unproven, while the missing security policy limits transparency.
62%
Total Score
63
100
83
83
All three workflow references are unpinned, and the auditor reports a high-confidence unpinned container-image finding. The workflow is otherwise fully analyzed with no untrusted checkout or script-injection findings.
One registry maintainer is consistent with an individually owned repository, but it leaves a limited apparent publishing base.
This is a 262-day-old package with only one release, so there is too little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a newly released package.
There are no open issues or pull requests and no recent issue or pull-request activity, providing no evidence of an active maintenance community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.