The package includes a clear README, matching MIT licensing, release notes, tests in the repository, and recent source updates. Maintenance is concentrated in one contributor, while workflows use broad permissions and unpinned actions; the missing security policy adds a smaller transparency concern.
64%
Total Score
50
100
50
A post-update-cmd lifecycle script runs during dependency updates, adding execution complexity beyond ordinary package installation.
All 3 recent commits came from one contributor, leaving maintenance dependent on a single active person.
The repository received 3 commits in the last 3 months, so work continues, but the activity level is light for a maintained library.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
Both workflows grant top-level write permissions and all 8 referenced actions are unpinned. The auditor also reported a low-confidence cache-poisoning pattern, which is a hygiene concern rather than a severe finding on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bdk/http-message Version ^1.3.4 || ^2.3.4 || ^3.3.4 | — | — |
jdorn/sql-formatter Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.