This is a small, clearly scoped and well-scaffolded package with a stable release, an active non-archived organization-owned repository, tests, explicit licensing, security scanning, and no install-time lifecycle scripts or dangerous workflow patterns. The main concern is limited release history—only three releases over 762 days—and no commits or active maintainers in the last three months, although a release and repository push occurred recently and a pull request was merged. It appears reasonable to depend on, with routine maintenance activity worth monitoring rather than evidence of abandonment.
78%
Total Score
88
100
89
90
The package has only three releases across 762 days, with one release in the last 12 months and a median interval of about 381 days; this indicates a slow maintenance cadence, though the latest release is recent.
There were zero commits and zero active maintainers in the last three months, which is a maintenance-capacity concern; the recent repository push and release provide only partial contextual compensation.
The repository has zero stars and one fork, indicating limited adoption or visibility, but popularity is supporting evidence and does not outweigh the package's focused scope and other health signals.
Neither workflow declares top-level token permissions, leaving GitHub Actions permissions less explicit than preferred; there are no observed top-level write permissions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.