The project has recent releases, active commits, a license, and read-only workflow permissions. Its single active contributor, absent README, repository name mismatch, and all 12 actions being unpinned leave meaningful maintenance and transparency concerns.
68%
Total Score
83
100
79
67
The artifact has no README, tests, or changelog, but missing tests and changelogs are normal for published artifacts; the exact version does have a GitHub release. The missing README still weakens consumer documentation for a library.
One contributor made all 5 commits in the last 3 months. Organization ownership provides some handoff capacity, but current activity remains concentrated.
The repository name does not match the package name, and no README package mention was found. Although name differences can occur in subpackages, the missing confirmation weakens confidence that this repository cleanly represents the package.
The repository has no published security policy. This is a transparency gap for a token and signing library, though it does not by itself show abandonment.
Version 0.4.5 is not a stable major release, but it is not a prerelease and recent releases contain no prerelease versions. This is a modest maturity limitation rather than a serious health concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lesname/value-object Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.