Usable with caveats: this is a clearly documented, newly published extension with organization backing and a matching repository, but it has no maintenance history yet and one release workflow uses write permissions. Prefer it after the project demonstrates sustained activity.
68%
Total Score
67
100
88
80
This is a brand-new package with one release and no release interval history, so its maintenance and release reliability are not yet demonstrated.
There were no commits or active maintainers in the measured three-month window. Because the package is only hours old, this is partly explained by its age, but sustained maintenance remains unproven.
Two pull requests were opened in the last month, but none were merged, so there is some activity without evidence yet of completed maintenance work.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
One workflow declares top-level write permissions while the other is read-only. Write access may be necessary for publishing, but it increases the impact of a compromised release workflow.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.