Healthy and reasonable to adopt, with a small maintenance risk. It is actively releasing, has repository tests and changelog coverage, and uses basic security tooling, but all recent commits come from one contributor and the project has very little community traction.
78%
Total Score
63
100
94
90
The repository is owned by an individual user rather than an organization, which makes the single-contributor maintenance concentration more consequential.
One contributor made all 12 recent commits, creating a genuine single-maintainer continuity risk. The project is user-owned rather than organization-backed, so there is no visible organizational handoff capacity to offset it.
Twelve commits in the last 3 months show ongoing work, but all were made by one active maintainer, limiting resilience if that person becomes unavailable.
The repository has one star and no forks, so there is little evidence of external adoption or community support. This is supporting caution rather than a severe health concern because release and repository activity are strong.
The CI workflow does not declare top-level token permissions. No write permissions were observed, but explicitly restricting the token would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.