Usable with caveats: this is a clearly documented, organization-backed extension with matching source and release automation, but it is brand new and has no demonstrated commit history yet. Treat it as an early-stage dependency until several releases establish maintenance continuity.
68%
Total Score
75
100
88
75
The package is 0 days old with only one release, so there is no release track record or evidence of sustained maintenance yet.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package was only published today, this may reflect its newness, but it provides no established maintenance evidence.
No security policy is present, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, though the package's other repository and workflow evidence partly reduces the concern.
One release workflow has top-level write permissions, which is broader than read-only access and increases the impact of a workflow compromise, although the other workflow is read-only.
Version v0.1.0 is an initial non-stable-major release, which indicates an early API and limited maturity even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.