Usable with caveats: this is a newly published package with no established release or commit history yet. It has a matching repository, tests, documentation, licensing, automated tooling, and no deprecation, but workflow permissions and the lack of a security policy warrant review before adopting it broadly.
62%
Total Score
67
100
88
50
One of six workflows uses pull_request_target for Dependabot automation; although no untrusted checkout or script injection was detected, this privileged workflow deserves review.
One registry publisher is consistent with the organization-backed project, but it still represents a narrow observed publishing base.
This is the first release and the package is 0 days old, so there is no demonstrated release cadence or production track record yet.
There were no commits or active maintainers in the preceding 3 months, but the repository and release are newly created, so this is limited evidence of abandonment rather than a severe failure.
No repository security policy is present, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.