Memory Efficient Serialization Library
73%
Total Score
63
100
100
88
50
No registry build attestation or trusted publisher identity is present, leaving publication provenance less transparent than it could be; the linked, matching repository and established release process provide partial context but not verified provenance.
One of six workflows uses pull_request_target, but no untrusted checkout or script-injection patterns were detected; the isolated elevated-trigger use warrants awareness but is not a severe health concern.
All recent commits came from one contributor, creating concentration risk; Google organization backing provides some ability to hand maintenance off but does not remove the current activity concern.
Only one commit was recorded in the last three months, with one active maintainer, which is a meaningful sign of slowing recent maintenance despite the recent package release.
The repository has ongoing intake—18 new issues and 37 new pull requests in one month—but closed only 6 issues and merged no pull requests, suggesting a growing backlog.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.