Usable with caveats: the package is licensed, documented, backed by an organization, and has repository tests and security tooling, but it has only one release and no commits or active maintainers for about 14 months. Review its compatibility carefully before adopting it as a long-term dependency.
58%
Total Score
50
78
67
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the single-release history, this is a meaningful maintenance and abandonment concern.
One of five workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can carry elevated workflow risk; no untrusted checkout or script-injection patterns were detected.
There has been only one release, published about 14 months ago, with no releases in the last 12 months. This leaves little evidence of an established release process or ongoing compatibility work.
The repository has zero stars, forks, and watchers. This is weak supporting evidence and is not decisive by itself, but it offers no external adoption signal to offset the inactive history.
The linked repository is not archived, although its last push was about 14 months ago, consistent with the lack of recent release activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.