It has a long release history, clear licensing, repository tests, substantial documentation, and no install-time scripts. The repository is active, correctly linked, and uses Dependabot, although its small footprint limits external reassurance.
78%
Total Score
50
100
100
75
The repository is owned by an individual account rather than an organization, so the concentrated maintainer activity has no visible organizational handoff support.
All three recent commits came from one contributor, leaving maintenance continuity dependent on a single person.
Three commits in the last three months show recent activity, though the volume is modest and comes from only one active maintainer.
No security policy is present, leaving vulnerability-reporting expectations undocumented; this is a transparency gap rather than evidence of unsafe code.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, weakening build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ilexn/result-option Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.