Healthy and suitable to use, with a small maintainer-base caveat. It has frequent recent releases, an active unarchived repository, source tests, and security tooling; all recent commits come from one contributor.
82%
Total Score
75
100
94
80
The repository is owned by the same individual namespace as the package, so the concentrated maintainer activity represents genuine single-person backing rather than organizational capacity.
All three recent commits came from one contributor, so maintenance depends heavily on a single person and may be fragile if that contributor stops work.
The repository has only 2 stars and 2 forks, indicating limited external adoption; popularity is supporting evidence rather than a decisive health measure, so this modestly limits confidence but does not make the package unsafe to use.
The repository has no security policy, leaving the process for reporting vulnerabilities undocumented; this is a transparency gap, but not by itself evidence of abandonment.
All workflows declare permissions, with four read-only workflows and four workflows granted top-level write access; explicit permissions are good hygiene, though write access increases workflow impact if compromised.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.