This is a reasonably healthy and usable release with strong repository and package transparency: it is MIT-licensed, non-deprecated, stable, actively released, recently pushed, tested, and backed by a substantial 148-file source tree. The main risks are that the project is young, all 28 recent commits come from one contributor, the repository has little recorded adoption, and it lacks a security policy; one workflow also omits top-level token permissions. These concerns warrant monitoring and contingency planning, but there is no evidence of abandonment or severe release hygiene failure.
78%
Total Score
60
100
89
80
Only one registry account has publish access. This is a modest continuity concern, although repository activity shows that the same maintainer is actively developing the project.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the concentrated maintainer base.
One contributor produced 100% of the 28 commits in the last three months, creating a meaningful continuity and bus-factor risk for a user-owned project.
There are no open issues or pull requests, and no recent issue or pull-request activity. This is neutral for a small project but provides little evidence of community support or responsiveness.
The repository has only 1 star and no forks, so external adoption and community validation are limited; popularity is supporting evidence rather than a verdict.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.