Good documentation, tests, release notes, and recent activity make the package easier to adopt. Unpinned workflow actions, no security policy, and a single active contributor leave maintenance and CI-hygiene concerns.
68%
Total Score
75
83
50
Four releases in 40 days, with a median interval of about 1 day, show active early development. The short history means long-term maintenance is not yet established.
All 31 recent commits came from one contributor, giving the project a complete single-person dependency for ongoing maintenance and review.
The repository has no security policy. This is a transparency gap for a library intended to be integrated into applications, though it is not evidence of a security defect.
v0.2.0 is not a stable major release and half of recent releases were prereleases, so compatibility expectations remain limited.
The only workflow was fully analyzed with no untrusted checkout or script-injection findings, but both of its action references are unpinned. That leaves avoidable build-integrity risk despite otherwise clean audit results.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.