Healthy and actively maintained, with clear packaging, tests, and recent releases. The main caveat is that all recent commits come from one contributor and the repository lacks a security policy and explicit workflow permissions.
78%
Total Score
80
100
94
80
Only one registry account has publishing access. Because the repository is owned by the same individual rather than an organization, this leaves limited publishing redundancy, although repository activity shows the maintainer is active.
One contributor made 100% of the 16 commits in the last three months. This creates a genuine continuity risk for an individually owned project.
The repository has one star and no forks or watchers. This is weak supporting evidence, but popularity alone does not outweigh the active release and commit signals.
The repository has no security policy. For a plugin handling AI-provider configuration, this is a transparency and vulnerability-reporting gap, though the repository does use automated security scanning.
All four workflows lack top-level token permissions, and none declares read-only permissions. Although no workflow requests top-level write access, explicit least-privilege declarations would provide better supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.