[![npm version][npm-v-src]][npm-v-href] [![npm downloads][npm-d-src]][npm-d-href] [![status][github-actions-src]][github-actions-href]
72%
Total Score
caution
Usable with caveats: no registry release for about 21 months, and recent repository work comes from one contributor.
The package has had no registry release for about 21 months, after nine releases over roughly eight years. This is a meaningful freshness concern, although the linked repository remains active.
All four recent commits came from one contributor, creating a thin immediate maintenance base. Organization backing provides some handoff capacity but does not remove the concentration risk.
Four commits from one active maintainer in the last three months show recent maintenance, but the low activity level does not fully offset the long registry release gap.
The project uses build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe concern.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a minor governance gap for a small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
consola Version ^3.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.