Documentation, repository tests, release notes, and MIT licensing make the package easy to inspect. The workflow audit is clean, but the package is too new to establish long-term reliability.
68%
Total Score
83
86
50
This package is only 0 days old with two releases, issued about 49 minutes apart, so its release and maintenance history cannot yet demonstrate durability.
All 41 recent commits came from one contributor, leaving maintenance continuity dependent on a single active developer. Organization backing provides some context but does not show a second active contributor.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Version 1.0.0-RC.0 is a prerelease and all recent releases are prereleases, so compatibility and API stability remain less certain than for a stable release.
Both workflows were analyzed successfully and use read-only permissions, with no untrusted checkouts, script injection, or audit findings. However, all 11 action references are unpinned, which weakens build reproducibility and action supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
longitude-one/spatial-types Version 0.0.1-alpha.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.