The matching source tree, MIT licensing, lightweight dependencies, and repository tests support straightforward use. The absent security policy and low project activity make long-term support less certain.
55%
Total Score
50
100
79
67
Only two releases exist, both from January 2023, with no release in the last 12 months. The repository was pushed more recently, but registry release activity still suggests weak release maintenance.
There were no commits and no active maintainers in the last three months. The 2025 push provides limited compensation, but current maintenance capacity remains uncertain.
The repository has no security policy. For a package intended to be integrated into applications, this is a transparency and support gap.
Version 0.0.2 is not a stable major release, which indicates an early-stage API. This is consistent with the package's small size but adds adoption risk.
All 9 action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. A pull_request_target trigger is not dangerous by itself, but the identified condition problem and weak pinning reduce workflow hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.