Terminus integration provides readiness/liveness health checks for NestJS.
82%
Total Score
88
100
94
63
The package has a prepare install-time lifecycle script. This is a small supply-chain and installation-complexity concern because the signal does not show why the hook is needed.
One contributor made 30 of 31 recent commits, so continuity depends heavily on a single person. The organization-owned repository and one additional active contributor partly compensate, making this a caution rather than a severe abandonment signal.
The repository uses TypeScript, Vitest, npm scripts, and Vite, but no security scanning tools were detected. The missing scanning automation is a modest transparency and hygiene gap.
No repository security policy was found. This weakens disclosure transparency, but active commits, releases, tests, and organization backing provide meaningful compensation.
All 6 workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 18 action references are unpinned, which leaves workflow dependencies less reproducible and increases maintenance risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.