It has a long release history, recent release notes, repository tests, and a security policy. Verify the source relationship because the repository neither matches the package name nor mentions it in the README.
82%
Total Score
83
92
100
One contributor made 100% of the 35 commits in the last 3 months. Organization backing provides some continuity, but no second active contributor is shown, leaving a real handoff risk.
The repository name does not match the package name and the README does not mention the package. A name mismatch can be normal for a subpackage, but the absence of any README mention warrants caution that the repository may not be the package's actual source.
All four workflows were analyzed successfully with no untrusted checkouts, script injection, or audit findings, and none grants top-level write access. All 5 action references are unpinned, which is a workflow reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bear/resource Version ^1.0 | — | — |
koriym/psr4list Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.