Healthy and actively maintained, with a clear license, regular releases, recent work from several contributors, and organization backing. The main caveats are the absence of tests and security scanning, plus one workflow with broad write permissions.
86%
Total Score
100
88
90
A README, changelog, and GitHub Releases are present, but neither the package nor repository includes tests; this is a real maintenance gap for a library, though it does not outweigh the active project evidence.
The repository uses a build tool, but no security scanning tools were detected; this is a transparency and assurance gap, partially offset by the repository's security policy and active organization ownership.
Workflow permissions are explicitly declared, but the npm publishing workflow has top-level write permissions; this is broader than necessary and increases release-automation exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.