It is clearly scoped, documented, tested, and licensed. Organization backing helps, but limited history and unpinned workflow actions leave maintenance and build-reproducibility concerns.
68%
Total Score
67
100
92
75
The package is only 50 days old, with six releases concentrated in a very short period; this shows activity but provides limited evidence of long-term maintenance.
One contributor made all two recent commits, creating a concentrated maintenance risk; organization backing provides some ability to hand work off.
Only two commits were recorded in the past three months, indicating limited observed maintenance activity for a package that is otherwise very new.
No repository security policy was found. This is a transparency gap, though it is less significant for a small presentation-layer package than for security-sensitive software.
All three workflows were analyzed with no high-confidence findings, unsafe triggers, or broad write permissions. However, all three action references are unpinned, leaving a build-reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.1 | — | — |
liberusoftware/blog-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.