The easiest way to configure your development environment with your GraphQL schema (supported by most tools, editors & IDEs)
84%
Total Score
healthy
Regular releases and active, distributed repository maintenance support this release.
No build attestation or trusted-publisher identity is present, so consumers receive no additional verification of how the artifact was produced.
The package has 11 runtime dependencies and no declared development dependencies. This is a meaningful dependency surface for a configuration library, but not by itself evidence of poor health.
The repository is organization-owned, and two publishing accounts use the organization domain. The consumer-domain accounts urigo (gmail.com), kamilkisiela (gmail.com), and ardatan (gmail.com) create some account-hygiene risk, though they do not indicate maintenance capacity.
The repository uses TypeScript, Vitest, Rollup, Vite, and npm scripts, indicating a structured build and test setup. No security-scanning tools were detected.
The repository has no security policy, leaving disclosure expectations undocumented. This is a transparency gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jiti Version ^2.0.0 | — | — |
tslib Version ^2.4.0 | — | — |
minimatch Version ^10.0.0 | — | — |
cosmiconfig Version ^8.1.0 | — | — |
@graphql-tools/load Version ^8.1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.