Get an available port
78%
Total Score
50
100
94
83
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable. This is a transparency gap, not evidence that the release is unsafe.
One registry publishing account is listed, which is a modest concentration concern, though the linked repository and recent release provide compensating evidence of ongoing ownership.
The repository is owned by a user account rather than an organization, so the single publishing account represents genuine maintainer concentration rather than organization-backed publishing.
The repository recorded no commits and no active maintainers in the last three months. The same-day release push shows current publication activity, but the broader recent development activity remains limited.
No build tool or security scanning tool was detected. The package is small and has no runtime dependencies, which reduces the significance of this tooling gap, but it still limits visible engineering controls.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.