Usable with caveats: this is a brand-new v0.1.0 package with no release track record, popularity, or demonstrated commit activity yet. It has clear documentation, tests in the repository, licensing, and no install scripts, but workflow permissions and the absence of a security policy merit review before adoption.
68%
Total Score
75
100
81
63
One of six workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection patterns were detected, but this privileged workflow warrants review because it can affect repository automation security.
The package was released only hours ago and has a single release, so there is not yet evidence of sustained maintenance or release stability. Its very recent creation makes the lack of history understandable but still limits confidence.
The repository records zero commits and zero active maintainers in the measured three-month window. Because the release is only hours old, this mainly reflects limited observation time, but maintenance capacity is not yet demonstrated.
The repository has zero stars, forks, and watchers. This is consistent with a package released today, but it provides no supporting evidence of community adoption or review.
The repository has no security policy, leaving vulnerability-reporting and response expectations unspecified. This is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.