The repository has tests, a clear README, a license, and recent commits. Its single-maintainer history, one-release track record, absent security policy, and unpinned workflow actions reduce confidence.
72%
Total Score
63
100
88
75
Only one registry account has publish access. That is consistent with a personal project, but it leaves little publishing redundancy for this young package.
The repository is owned by an individual user rather than an organization, so there is no demonstrated organizational handoff capacity to offset the concentrated maintainer activity.
This package is only 61 days old and has one release, so there is not yet enough release history to demonstrate long-term maintenance or compatibility stability.
One contributor made all 9 commits in the past 3 months, giving the project a complete single-person bus factor. This is a meaningful continuity risk for a young library.
The repository has no security policy. For a library intended to be integrated into applications, this weakens the project's documented vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.