This release appears healthy and suitable for dependency use: it is actively released, stable, non-deprecated, backed by a matching organization-owned repository, and supported by clear documentation, build tooling, security scanning, and repository tests. The main concerns are that recent commit activity is entirely concentrated in one contributor and the repository lacks a security policy and explicit top-level workflow permissions; these are meaningful hygiene and continuity risks, but they do not outweigh the strong maintenance and transparency evidence.
82%
Total Score
90
100
100
80
All 38 recent commits were made by one contributor, giving the project a highly concentrated bus factor and creating a genuine continuity risk if that contributor becomes unavailable. Organization backing partially mitigates handoff risk but does not remove the concentration concern.
No repository security policy was found, reducing transparency around vulnerability reporting and response procedures. This is a hygiene gap, though security scanning is present.
The CI workflow does not declare top-level token permissions. Although no top-level write permissions were observed, the absence of an explicit restrictive declaration leaves workflow authorization less clear than best practice.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.