The missing security policy and unpinned workflow actions reduce transparency and build reproducibility. A small dependency surface, a clear repository match, and a documented release note provide useful safeguards.
68%
Total Score
50
100
88
75
The repository is owned by an individual rather than an organization, so the single registry maintainer reflects a genuinely narrow apparent ownership base.
The package has existed for about 4 years and has 12 releases, but only one release occurred in the last 12 months, indicating a slower current cadence.
There were no commits and no active maintainers in the last 3 months, a concrete sign that maintenance has paused recently; the recent release and repository push provide only partial compensation.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.10.0 is not a stable major version, so compatibility expectations are weaker, although it is not marked as a prerelease and recent versions are consistently stable.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.