The package is clearly licensed, has release notes, a focused dependency set, and an organization-backed repository with recent activity. Its automation needs tightening, especially because every referenced action is unpinned and publishing relies on long-lived credentials.
67%
Total Score
67
100
83
75
The package has eight releases, but all occurred within roughly five days and the package is only 141 days old, so its longer-term release pattern is not yet established.
One contributor made all commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
Only one commit was recorded in the last three months, showing limited recent activity; the recent push provides some evidence of continued maintenance but not a strong cadence.
The repository has only two stars and no forks or watchers, so there is little external adoption evidence; this is supporting context rather than a decisive health problem.
No repository security policy was found, leaving vulnerability-reporting guidance unclear for a package intended for application integration.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.