The package is stable, has a README and repository tests, and has no install-time scripts. Its small single-user footprint and unpinned CI references add maintenance and build-hygiene concerns.
58%
Total Score
50
100
92
75
One registry maintainer is responsible for publishing the package. The matching repository and clear ownership help, but the narrow maintainer base leaves limited visible continuity.
The latest release was over four years ago, with no releases in the last 12 months and only three releases overall. This is substantial evidence of slowing maintenance.
The repository had no commits and no active maintainers in the last three months, consistent with the long release gap and raising abandonment concerns.
The repository has no security policy. This is a transparency gap, although it is less concerning for a small, stable library than the lack of recent maintenance.
Both workflows were analyzed successfully and had no reported dangerous findings, but all three action references are unpinned. That creates a build-integrity hygiene gap without evidence of an exploitable workflow path.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.