This release appears healthy and suitable for dependency use: it has a stable v13 release, a five-year history with 73 releases and nine releases in the last 12 months, current repository activity, tests, changelog and README coverage, a matching organization-owned repository, and security tooling. The main concern is maintenance concentration: only one contributor made the two commits in the last three months, while the repository also lacks a security policy and does not declare top-level workflow token permissions. These are meaningful hygiene and continuity gaps, but they are moderated by the organization backing, active release cadence, merged pull requests, and otherwise solid project structure.
82%
Total Score
80
100
94
80
All two recent commits came from a single contributor, creating a continuity risk; organization backing partially compensates because maintenance can potentially be handed off within the organization.
There were two commits in the last three months from one active maintainer, showing recent work but relatively low recent commit volume.
The repository has only 1 star, 0 forks, and 1 watcher, indicating limited external adoption; this is supporting caution rather than a verdict because the package otherwise shows active maintenance and coherent structure.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting guidance less transparent than ideal.
The one workflow lacks top-level token permissions and uses job-level permissions only; there are no top-level write permissions, so this is a workflow-hygiene gap rather than a severe excessive-permission finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lion/phroute Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.