Its Apache-2.0 licensing, clear README, and minimal dependency footprint make adoption straightforward. The small project has little recent community activity, so future fixes and support may be limited.
58%
Total Score
50
100
88
67
The package has had no release in over three years, with only four releases overall and none in the last 12 months. That materially raises abandonment risk despite its earlier roughly 49-day median release interval.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release gap and indicating limited evidence of ongoing maintenance.
Two stars, no forks, and one watcher show a very small user and contributor footprint. Popularity is only supporting evidence, but this provides little external maintenance capacity to offset inactivity.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is less serious for this small, simple package than for a security-sensitive component.
The single workflow is fully analyzed, uses read-only permissions, and has no flagged findings, but both of its two action references are unpinned. That is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.