The package is small and easy to inspect, with no runtime dependencies and a complete README, tests, and changelog. Its lone maintainer and unpinned workflow actions add modest operational risk, while the lack of recent activity is the main concern.
58%
Total Score
38
100
83
75
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive since its initial release. This is the strongest abandonment signal.
One registry maintainer is listed. Because the repository is owned by an individual rather than an organization, this indicates a thin maintainer base, though it is not severe on its own.
The repository is owned by an individual user, not an organization, so there is no organizational backing to compensate for the thin maintainer base or long inactivity.
This is the only release, published nearly five years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, although a template can remain stable after its initial release.
There are no open issues or pull requests and no recent activity. That is orderly, but it also offers no evidence of an active maintenance process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.