The package includes tests, a license, and only one runtime dependency, which keeps adoption straightforward. Its post-install script, missing security policy, and unpinned workflow action add modest operational risk.
58%
Total Score
50
100
81
50
There were no commits and no active maintainers in the last three months, while the latest repository push was over 16 months ago. This is the strongest evidence of stalled maintenance.
A post-install command runs during installation, adding execution behavior and some supply-chain exposure beyond ordinary dependency resolution.
A single registry maintainer creates a thin publishing base. The matching personal repository provides some continuity, but there is no broader maintainer redundancy shown.
This is the only release, published about 16 months ago, with no releases in the last 12 months. That leaves limited evidence of ongoing maintenance.
The project uses Make and Composer, but no security-scanning tools were detected. That is a transparency and hygiene gap, not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.