The package is focused, documented, licensed, and has no runtime dependencies. Recent releases and an active repository help offset its limited maintainer depth, while workflow hygiene remains an area to improve.
70%
Total Score
83
100
100
67
All three recent commits came from one contributor, so maintenance is concentrated despite the repository being organization-owned; no second active contributor is shown.
The repository has no security policy. This is a transparency gap for reporting and handling security issues, although it does not by itself show abandonment.
All five analyzed action references are unpinned, and a high-confidence audit finding reports installing a package outside a lockfile; the low-confidence cache-poisoning finding is only hygiene evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.