Clear documentation, tests, release notes, and a read-only workflow support adoption. Maintenance is concentrated in one contributor, activity is light, and all workflow actions are unpinned. The missing security policy is a smaller transparency gap.
70%
Total Score
50
100
93
67
The repository is owned by an individual rather than an organization, so the single-contributor maintenance concentration is not offset by visible organizational handoff capacity.
The package is mature at 4443 days old and published two releases in the last 12 months, but its seven-release history and roughly 434-day median interval show a generally slow cadence.
All three-month commit activity comes from one contributor, leaving no demonstrated handoff capacity if that person becomes unavailable.
There was one commit in the last three months from one active maintainer; the recent push is positive, but the low activity provides limited evidence of sustained maintenance capacity.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented for a dependency consumers may integrate.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.