Testing and release notes improve transparency, while security documentation is absent and all two workflow actions are unpinned. Maintenance depends on one active contributor, so continuity is the main limitation.
76%
Total Score
50
100
100
67
The repository is owned by an individual user rather than an organization, so the single-contributor maintenance concentration has no shown organizational handoff support.
One contributor made all two recent commits, concentrating current maintenance responsibility in a single person.
Only two commits were recorded in the last three months, showing limited recent development activity despite the strong release history.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jpi/utils Version ^1.0 | — | — |
jpi/database Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.