The package includes tests, release notes, a clear README, an MIT declaration, and security scanning, with no install-time scripts. Its GitHub Actions references are all unpinned, and no security policy is published.
62%
Total Score
75
86
75
The package is only 36 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance.
One contributor made all 31 commits in the last three months, leaving no demonstrated second maintainer to provide continuity if that contributor becomes unavailable.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for users of this library.
Version v0.1.0 is not a stable major release, which signals an early-stage API and greater compatibility risk despite not being marked as a prerelease.
The workflow audit completed successfully with no injection or high-confidence findings, but all three action references are unpinned, reducing build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
opis/json-schema Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.