Generate a URL for opening a new GitHub release with prefilled tag, body, and other fields
67%
Total Score
50
100
89
88
The repository is owned by an individual account rather than an organization, so there is no organizational backing signal to offset the thin maintenance activity.
The package has only three releases and none in the last five years, with a median release interval of about 525 days. This is a meaningful maintenance concern, although the package is small and its latest release is stable.
There were no commits and no active maintainers in the last three months. The recent repository push counters this somewhat, but the observed coding activity still suggests limited ongoing maintenance.
The repository reports no build tool and no security scanning tool. For this small package the lack of a build tool is unsurprising, but absent security scanning is a minor transparency gap.
The single workflow was fully analyzed with no injection, untrusted-checkout, or high-confidence audit findings. Both action references are unpinned, which leaves them less reproducible and creates a modest workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
type-fest Version ^2.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.