Check whether an npm package, GitHub Action, MCP server or Docker image is dead or abandoned.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Check whether an npm package, GitHub Action, MCP server or Docker image is dead or abandoned.