The package is well documented and licensed, with repository tests, active issue handling, security scanning, and a security policy. Its short history provides limited evidence of long-term stability.
70%
Total Score
75
100
89
83
The repository is owned by a personal user account rather than an organization, so the concentrated two-contributor maintenance pattern has no visible organizational handoff benefit.
Two contributors were active, but one made about 91% of the recent commits. The second contributor provides some continuity, yet ownership remains highly concentrated.
The repository has four stars and no forks, so external adoption evidence is limited. Popularity is supporting evidence only and does not outweigh the strong activity signals.
Version 0.20.44 is not a prerelease, but the package remains below 1.0, so compatibility expectations are less established than for a stable-major release.
All 47 analyzed action references are unpinned, which weakens build reproducibility, and one high-confidence template-injection finding was reported in ci.yml. No untrusted checkout or script-injection sink was found, so these are workflow-hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/agent-map Version ^0.18.0 | — | — |
helgesverre/toon Version ^3.1 | — | — |
voku/agent-kanban Version ^0.4.4 | — | — |
voku/agent-session Version ^0.7.1 | — | — |
voku/portable-utf8 Version ^6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.