The package includes tests, a README, release notes, and a matching license. Its workflow uses unpinned actions, and its maintenance record is too new to establish staying power.
68%
Total Score
100
83
67
This is the package's first release, published today, so there is no release track record or demonstrated maintenance cadence yet.
The linked repository has no security policy, leaving vulnerability-reporting and disclosure expectations undocumented; this is a modest transparency gap for a new library.
The release is not marked as a prerelease, but v0.11.0 is still below a stable major version and has no historical release pattern to support maturity.
All 2 analyzed action references are unpinned, which weakens build reproducibility. The workflow has read-only permissions, no untrusted checkout or script-injection findings, and the audit completed fully.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 || ^8.0 | — | — |
opis/json-schema Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.