Downgrade errors to warnings
72%
Total Score
63
100
95
63
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable.
A prepublish script is present, adding some release-process complexity, but this signal alone does not show an unsafe install-time action.
Only one registry account has publishing access, creating a thin publishing base, though this administrative count does not by itself show whether project work is active.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to offset the thin maintainer base.
The repository recorded no commits and no active maintainers during the last three months, which weakens evidence of ongoing maintenance despite the recent release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.