Usable with caveats: it is a small, transparent package with tests, licensing, and security tooling, but it has had no release or repository activity since December 2020. Depend on it only if its stable, narrow functionality fits your needs and you can maintain it yourself.
58%
Total Score
50
100
79
88
The package has only one release, published about 5 years and 9 months ago, with no releases in the last 12 months. This strongly limits evidence of ongoing maintenance and compatibility work.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the only release. This is the strongest maintenance risk in the assessment.
The repository is not archived, but its last push was about 5 years and 9 months ago. It remains available, yet the lack of recent maintenance is a meaningful abandonment concern.
Neither workflow declares top-level token permissions, and neither grants top-level write access. Explicit least-privilege declarations would be clearer, but no write-enabled workflow was observed.
Version 0.0.1 is not a stable major release, so API compatibility and maturity are less established. The absence of prereleases provides a small compensating signal, but does not offset the package's long inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.