Clear licensing, documentation, tests, and changelog in the source repository support dependable use. Recent publishing is reassuring, but no commits in the last 3 months and two unpinned workflow actions leave maintenance and build-integrity concerns.
68%
Total Score
67
100
100
75
The package and repository are owned by the same individual account, so the source linkage is clear, but there is no organization backing shown to broaden maintenance capacity.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful maintenance concern even though a release was published recently.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear for a parser library.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned, weakening build reproducibility and protection against action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.