Documentation and security transparency are thin, with no README, tests, changelog, or security policy collected. The repository is substantial and releases are frequent, but the linked repository does not clearly match the package name.
68%
Total Score
70
78
90
Only one registry account has publish access. This is a narrow publishing base, although the repository's recent activity shows that the maintainer is currently active.
The release includes GitHub release notes for this version, but it has no README, tests, or changelog in the collected package metadata. The missing tests and changelog are normal for published artifacts, while the missing README weakens consumer transparency for this framework library.
The repository owner is an individual user rather than an organization, so the concentrated maintenance and publishing responsibility is not visibly backed by a broader project team.
All 57 recent commits came from one contributor, leaving no demonstrated handoff capacity if that person becomes unavailable.
The repository name does not match the package name, and no README mention was collected, so the source-to-package relationship is not clearly established by this signal.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.