The repository has no stars and does not identify the package in its README, which weakens confidence in project ownership. Tests, a clear GPL-2.0-only declaration, and no install scripts are helpful, but they do not offset the limited activity.
44%
Total Score
81
75
The latest release was published on 2024-07-07, with no releases in over two years by the collection date. That is a substantial abandonment concern for a dependency, despite the package having eight releases overall.
The linked repository name does not match the package name and its README does not mention the package. This weakens confidence that the repository clearly represents the published package.
The repository has zero stars and zero forks, with one watcher. Popularity is not required for health, but these figures provide little supporting evidence of adoption or community visibility.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not evidence of a security defect by itself.
No GitHub Actions workflows were present, so the audit found no workflow vulnerabilities. This provides no evidence of automated build or release assurance, but the absence of workflows is not itself a defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
henrik/component Version ^2.3 | — | — |
henrik/container Version ^2.0.2 | — | — |
henrik/contracts Version dev-main | — | — |
henrik/filesystem Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.