Its 14 runtime dependencies increase upgrade surface, while the single registry maintainer limits visible continuity. The MIT license and matching repository make reuse straightforward, but no security policy leaves little published security process.
48%
Total Score
33
50
79
83
The package has 29 releases but none in the last 12 months; its latest release was over two years ago, which raises abandonment risk despite a previously active cadence.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance.
Fourteen runtime dependencies create a substantial compatibility and upgrade surface for a small package, increasing maintenance exposure when release activity has stopped.
One registry maintainer concentrates publishing responsibility and offers limited visible continuity, although this does not by itself show that repository work is unsupported.
The registry namespace and repository owner match, but the owner is a user account rather than an organization, so there is no demonstrated organizational backing to offset the thin maintainer base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
goldfinch/taz Version ^2.0 | — | — |
goldfinch/mill Version ^2.0 | — | — |
goldfinch/fielder Version ^2.0 | — | — |
goldfinch/harvest Version ^2.0 | — | — |
goldfinch/helpers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.