Usable with caveats: it is actively maintained and well documented, with tests, a clear license, and no deprecation or workflow red flags. However, it is only 51 days old, releases arrive roughly every 42 minutes, and all recent commits come from one maintainer without a security policy.
72%
Total Score
60
100
83
75
Only one registry account has publish access. This is a real continuity concern for an independently owned project, although repository activity confirms that the same maintainer is actively publishing and committing.
The repository is owned by a user account rather than an organization, so the project has no demonstrated organizational backing to offset its single-maintainer structure.
The package is only 51 days old but has 77 releases, with releases arriving roughly every 42 minutes. This shows strong activity but also an unusually rapid cadence that makes maturity and release discipline harder to establish.
One contributor made all 120 commits in the last 3 months, creating a concentrated continuity risk. The project is user-backed rather than organization-owned, so there is no provided organizational handoff signal to compensate for that concentration.
There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral for a young project, but it provides little evidence of community review or support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.