Clear documentation, tests, and release notes make the package easy to evaluate and integrate. The project is very new, maintained by one contributor, and its workflow uses five unpinned actions without a security policy.
68%
Total Score
67
100
93
75
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
This is a very new package, only 42 days old, with one release and no established release cadence. That limits evidence of long-term maintenance.
All five recent commits came from one contributor, so maintenance depends entirely on a single person and has limited resilience.
The repository has no security policy. For a small color-conversion library this is a modest transparency gap, but it leaves no documented vulnerability-reporting path.
The workflow has read-only permissions and no audited dangerous findings, but all five action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.