The package is licensed, clearly linked to its repository, and includes release notes and a usable README. Organization backing helps offset the one registry maintainer, but recent commit activity is absent, workflow actions are unpinned, and no security policy is present.
62%
Total Score
75
93
75
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance and abandonment concern.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package intended for application integration.
Version v0.1.9 is not a prerelease, though the package remains before a stable 1.0 major release, so maturity is somewhat limited.
The workflow audit completed cleanly with no dangerous triggers or findings, but all seven action references are unpinned, leaving builds exposed to future action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
decodelabs/atlas Version ^0.14 | — | — |
decodelabs/nuance Version ^0.2 | — | — |
decodelabs/coercion Version ^0.3.4 | — | — |
decodelabs/exceptional Version ^0.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.