Usable with caveats: this is a clearly documented, organization-backed extension with minimal runtime dependencies and no deprecation or workflow red flags. It is brand new with no demonstrated commit history, and its release workflow grants write access, so maintenance and publishing practices are not yet proven.
72%
Total Score
67
100
86
80
This is the first release and the package is only 0 days old, so there is no history demonstrating sustained maintenance or reliable release cadence.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository and package were created today, so this is weak evidence of abandonment rather than a severe risk.
Two pull requests were opened in the last month, showing some activity, but none were merged and there are no closed issues to demonstrate completed maintenance work.
No security policy is present, leaving vulnerability-reporting expectations unclear for a package that distributes native binaries.
One workflow declares top-level write permissions, which is broader publishing authority than read-only access and increases the impact of a compromised workflow, although the other workflow is read-only.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.