68%
Total Score
100
100
78
75
The artifact includes a README, while the repository has tests, a changelog, and GitHub release tooling. The README explicitly describes this as an internal package and warns of unexpected breaking changes, which is a material adoption concern despite the repository hygiene.
The package has 909 releases over more than four years, but only one release in the last 12 months. The large historical release count shows activity, while the recent pause leaves some uncertainty about ongoing package-level maintenance.
The linked repository name does not match the package name and its README does not mention the package. A monorepo can legitimately contain subpackages, but the lack of any package reference makes the source-to-artifact relationship less transparent.
The repository has no security policy, leaving vulnerability reporting and response guidance undocumented. This is a transparency gap, though it does not by itself show abandonment.
Five of six workflows lack top-level permission declarations, and the release workflow has top-level write permissions. The active project and absence of detected dangerous workflow patterns provide some compensation, but least-privilege configuration is not consistently documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.8.1 | — | — |
@repeaterjs/repeater Version ^3.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.