Healthy and suitable to use. It has frequent recent releases, active source maintenance, licensing, provenance, and safe workflow settings; the main caveat is that recent commits are heavily concentrated in one contributor and repository security tooling is limited.
86%
Total Score
88
100
94
100
100
One contributor made about 97.6% of the 166 recent commits, creating concentration risk; the organization-owned repository and two additional active contributors partly compensate, but the concentration remains a caveat.
No build tool or security scanning tool was detected, which is a transparency and maintenance gap, although the repository still has active commits and a security policy.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-480676 js-yaml is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 4.3.0. | 3.0.0 - 4.3.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.mvnpm:argparse Version [2.0.1,3) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.