Create a promise that can be canceled
68%
Total Score
67
100
90
90
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable, although this is a transparency limitation rather than evidence that the package is unsafe.
The matching repository is owned by an individual account rather than an organization, so the project has a narrower formal backing structure, but the repository identity is clear.
The package has existed since 2016 with 15 releases, but its latest registry release was July 2022 and it had no releases in the last 12 months, indicating a potentially slow maintenance cycle.
There were no commits and no active maintainers in the latest three months, which is a meaningful sign of currently limited maintenance capacity; the 2025 push provides some compensating evidence but does not show ongoing activity.
The repository reports no build or security-scanning tools, a modest transparency and maintenance gap, but the package is small and its artifact is straightforward.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.