It has a clear MIT license, repository tests, and no install-time scripts. A small project footprint and unpinned workflow actions limit confidence in long-term maintenance and build assurance.
58%
Total Score
50
90
67
Only one registry publishing account is listed. That is a limited publishing base, though the linked repository identifies a matching individual owner rather than an unexplained publisher.
The package has 8 releases over roughly 8 years, but none in the last 12 months and the latest release was over a year ago, indicating slow maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is consistent with the stale release cadence and raises abandonment concern.
The repository has no security policy. For a form-processing library, this reduces the transparency of vulnerability reporting and maintenance expectations.
The single workflow was fully analyzed with no untrusted checkouts or script-injection findings, but both action references are unpinned. The lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
datatypes/datatypes Version ^3.0 | — | — |
bluemvc/bluemvc-core Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.