Its README, tests, MIT declaration, and minimal dependency footprint make the small library easy to inspect. The single maintainer and unpinned workflow actions leave limited maintenance and build-reproducibility margin.
58%
Total Score
50
100
92
Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer becomes unavailable.
The package has had no release in nearly 16 months, despite four releases arriving within a short initial window. This indicates a real maintenance concern, though a small stable library may need fewer releases.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap. That weakens evidence of ongoing maintenance.
The workflow was fully analyzed with no detected injection or high-severity findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions reduce build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.