The source project has tests, release notes, a clear license, and organization backing, with no deprecation or archive status. Its maintenance evidence is weaker than its packaging quality, so pinning this version deserves caution.
62%
Total Score
50
88
50
The latest release was published over four years ago, with no releases in the last 12 months. This is a meaningful maintenance concern for a dependency, despite a previously regular median release interval of about 132 days.
No commits or active maintainers were recorded in the last three months. This weakens the otherwise positive repository evidence and raises abandonment risk.
There are 26 open issues and 3 open pull requests, but no issues or pull requests were opened or closed in the last month. This indicates unresolved maintenance demand and limited recent responsiveness.
No repository security policy was found, leaving disclosure and response expectations less transparent for a package that integrates with external services.
All three workflows were analyzed without dangerous triggers or audit findings, but all 11 action references are unpinned. That is a supply-chain hygiene gap, partially offset by the absence of untrusted checkouts and script-injection findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wearerequired/traduttore-registry Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.