Healthy and suitable to use, with a small maintenance caveat. It has recent releases, matching organization-backed source code, tests, documentation, and active automation; recent repository work is concentrated entirely in one contributor, which increases continuity risk.
88%
Total Score
83
100
100
80
All six recent commits came from one contributor, giving the project a thin active contributor base. Organization backing partly offsets handoff risk, but continuity still depends heavily on one person.
No repository security policy is present. This is a transparency gap, though the package still has active releases and dependency scanning.
One workflow lacks top-level permissions and another grants top-level write access, leaving workflow privileges broader or less explicit than ideal. The absence of other dangerous workflow patterns provides partial reassurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roots/acorn Version ^4.0 || ^5.0 || ^6.0 | — | — |
millipress/millicache Version ^1.8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.