An exchange for operation retry support in urql
72%
Total Score
caution
Usable with caveats: no releases in the past year, plus repository and workflow hygiene gaps.
The package has 64 releases since March 2020, but none in the last 12 months; the latest release was over a year before collection. This is a maintenance concern, though repository activity remains present.
The repository name does not match the package and its README does not mention this package, so package-to-source ownership is less transparent. The broader repository structure indicates a monorepo, which partly explains the name mismatch but not the missing mention.
The project uses established build and test tooling, but no security scanning tools were detected. This is a modest transparency gap rather than a dependency blocker.
The linked repository has no security policy, leaving vulnerability reporting and response expectations less explicit for users.
All three workflows were analyzed successfully and use pinned actions without untrusted checkouts or script injection. A high-confidence low-severity adhoc-packages finding in the release workflow is still a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wonka Version ^6.3.2 | — | — |
@urql/core Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.