Healthy and suitable to use. It has frequent releases, current repository activity, tests, a clear license, and organization backing; maintenance is concentrated in one recent contributor and the repository lacks a security policy.
82%
Total Score
67
93
75
All 4 recent commits came from one contributor. Organization ownership provides some ability to hand off maintenance, but the observed contributor base remains concentrated.
There were 4 commits in the last 3 months and one active maintainer, showing recent work but a relatively modest maintenance pace.
The repository has 2 stars and 1 fork, indicating limited community adoption. Popularity is only supporting evidence, so this modest footprint does not by itself make the package unsafe to use.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations. The absence is a hygiene concern rather than evidence that the package is unsafe.
The sole workflow has no top-level GitHub Actions permissions declaration. Although it requests no top-level write permissions, explicitly constraining permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zozlak/argparse Version ^1 | — | — |
whikloj/bagittools Version ^6 | — | — |
acdh-oeaw/arche-assets Version ^3.9.4 | — | — |
acdh-oeaw/arche-lib-ingest Version ^4 | ^5 | — | — |
eclipxe/xmlschemavalidator Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.