The MIT license, small dependency set, and release notes improve transparency. Organization backing and a recent release provide useful continuity despite limited recent commit activity.
69%
Total Score
75
100
100
50
The repository recorded zero commits and zero active maintainers in the past three months. A recent release and one merged pull request provide some compensating evidence, but the short-term coding inactivity remains a maintenance concern.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is not evidence of a vulnerability by itself.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or high-severity findings, and neither grants top-level write access. However, all six referenced actions are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.