86%
Total Score
healthy
Active releases and maintenance keep this release healthy despite workflow, security-policy, and contributor-account gaps.
Five accounts can publish, including two using the the-guild.dev domain and three named accounts using gmail.com addresses: ardatan, kamilkisiela, and urigo. The company-domain accounts provide some continuity, but the outside mailbox accounts are an account-hygiene caution.
The repository owner is an individual account rather than an organization account, so organizational handoff capacity cannot be credited. The active maintainers and release history still provide substantial backing evidence.
Five contributors were active, but the top contributor made 64.5% of recent commits and the second made 31.8%. The active second contributor partly offsets the concentration, but the project still has a meaningful contributor-continuity caution.
The linked repository has no security policy file, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, though it is not evidence of abandonment by itself.
All seven workflows were analyzed, all 27 action references are pinned, and no untrusted checkout or script-injection paths were found. However, the audit reports a high-confidence archived action and trusted publishing using a long-lived registry token, so workflow hygiene remains a caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jiti Version ^2.3.0 | — | — |
yaml Version ^2.3.1 | — | — |
chalk Version ^5.6.0 | — | — |
tslib Version ^2.4.0 | — | — |
yargs Version ^18.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.