Usable with caveats: the release is well documented, licensed, and backed by a matching repository with tests and build security checks. However, it is brand new, with no established release or commit history, and the repository lacks a security policy and explicit workflow permissions.
68%
Total Score
50
100
94
75
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing for a project with no maintenance history.
The package was first released today and has only three releases, all within roughly 8 hours, so there is not yet enough history to demonstrate sustained maintenance or stability.
There were no commits or active maintainers in the preceding three months. Because the project was only created today, this is mainly a lack of maintenance history rather than evidence of a collapsed project, but it remains an adoption concern.
No repository security policy was found. This weakens vulnerability-reporting transparency, although the repository does provide Semgrep scanning.
The single workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege settings would provide stronger workflow controls.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.