The package includes tests, a useful README, a clear MIT license, and a small runtime dependency surface. Its release activity stopped about 15 months ago, and the workflow uses an unpinned container image; verify compatibility before adopting it for a long-lived project.
62%
Total Score
100
100
90
67
The package has had no releases in the last 12 months, and its latest release was about 15 months ago. That suggests maintenance may have stopped, despite five releases shortly after its initial publication.
The linked repository has no security policy. This is a transparency gap for reporting vulnerabilities, although the package is small and the absence does not by itself indicate unsafe code.
The single workflow was fully analyzed, but it uses an unpinned container image with high confidence. This weakens build reproducibility and CI supply-chain hygiene, though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.