This release appears safe to depend on from a supply-chain health perspective: it has a long release history dating to 2013, a current stable release, recent publication activity, an unarchived organization-backed repository, active and reasonably distributed contributors, comprehensive tests and changelog coverage, and strong build and security automation. The main limitations are the absence of a repository security policy and one workflow with top-level write permissions, but these are contained hygiene concerns rather than evidence of abandonment or unfitness. Several other health dimensions were not collected, so the score is not fully certain.
93%
Total Score
100
100
100
80
No repository security policy was found, which is a transparency and vulnerability-reporting gap; active maintenance and CodeQL/Dependabot coverage partly compensate but do not eliminate it.
Eight workflows declare read-only permissions, but codeql-analysis.yml has top-level write permissions, creating a limited least-privilege concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.