Check if the process is running inside a container (Docker/Podman)
68%
Total Score
50
100
89
88
50
No build attestation or trusted-publisher provenance is available, so consumers have less evidence connecting the published artifact to its source. This is a transparency gap rather than a health verdict by itself.
A single registry maintainer is a narrow publishing base, although the linked repository identifies the same owner and the package is directly backed by that project.
The repository is owned by an individual rather than an organization, so there is no organizational continuity signal to offset the narrow maintainer base.
There has been only one release, and no releases in the last 12 months; the latest release is nearly three years old. This may be acceptable for a small utility, but it leaves little evidence of ongoing release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating little current maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
is-docker Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.