The MIT license and matching package repository provide useful transparency. It has no security scanning, tests, or security policy, and its runtime dependency set is sizable.
45%
Total Score
38
50
72
83
The package has 35 releases, but its latest release was over two years ago and there were no releases in the last 12 months. The earlier release cadence does not compensate for the prolonged pause.
There were zero commits and zero active maintainers in the last three months, consistent with the release pause and indicating a serious abandonment risk.
The package declares 15 runtime dependencies and no development dependencies. This is a substantial integration surface and provides little evidence of a maintained test setup, though the dependencies are relevant to its framework component.
Only one account has registry publish access. The matching repository owner provides some continuity, but ownership is an individual user rather than an organization, leaving a thin publishing and maintenance base.
The artifact includes a README, but it is empty and neither the package nor repository reports tests or a changelog. Missing tests and changelog are normal packaging practice, while the empty consumer documentation is a minor transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
goldfinch/taz Version ^2.0 | — | — |
goldfinch/date Version ^1.0 | — | — |
goldfinch/mill Version ^2.0 | — | — |
goldfinch/nest Version ^1.0 | — | — |
goldfinch/fielder Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.