Clear licensing, tests, release notes, and a minimal dependency set make adoption straightforward. The repository is not archived and the release is stable, but package identity, maintenance activity, and workflow pinning leave meaningful uncertainty.
58%
Total Score
50
100
86
75
Only two releases were published, with the latest in November 2023 and none in the last 12 months. This indicates a small, mature-looking release history but also substantial inactivity for a package still being considered.
The repository recorded no commits and no active maintainers in the last three months. That weakens evidence of ongoing maintenance, although the package is small and may require few changes.
The repository name does not match the package name and its README does not mention this package. That raises uncertainty about whether the linked repository is the intended source.
No security policy is present in the repository. For a small package this is a transparency gap, though it is not evidence of abandonment by itself.
The single workflow was fully analyzed with no audit findings or untrusted-code sinks, but both action references are unpinned. This is a workflow hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.