The project includes tests, clear documentation, a matching source repository, and a recent release note. Its single maintainer, stalled release and commit activity, and unpinned workflow actions add ongoing maintenance and build-integrity concerns.
64%
Total Score
50
93
83
One registry maintainer is responsible for publishing the package. The matching user-owned repository supports clear ownership, but the narrow maintainer base increases continuity risk.
The package has had three releases, but none in the last 12 months and its latest release was about 15 months ago. This is a meaningful maintenance concern, though the repository was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent repository push provides limited compensation but does not show sustained activity.
The linked repository has no security policy. This is a transparency gap, although the package has no reported workflow audit findings and uses Dependabot for scanning.
The workflow is fully analyzed, uses read-only permissions, and has no reported audit findings, but all three action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
withinboredom/records Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.