This is a young but actively maintained package with a clear MIT license, matching repository, complete source scaffolding, repository tests, changelog, security policy, Dependabot, and recent release activity. The main concerns are its short 31-day history, pre-1.0 version, single active contributor, and GitHub Actions permissions that are broader than necessary; these warrant caution for long-term dependency adoption, although the organization-owned repository and recent merged pull requests provide some backing and maintenance evidence.
72%
Total Score
70
100
83
80
One workflow uses pull_request_target for Dependabot auto-merge, which carries elevated workflow risk, although no untrusted checkout or script injection was detected.
Only one registry account has publish access, which is a modest publishing continuity concern; the organization-owned repository provides some compensating project backing.
The package is only 31 days old with two releases about 31 days apart, so its maintenance and compatibility track record are still limited.
All 11 recent commits came from one contributor, creating a real bus-factor risk; organization ownership provides some potential handoff capacity but does not demonstrate a second active maintainer.
Eleven commits occurred in the last three months, but all were made by one active maintainer; activity is recent but the contributor base is thin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orchestra/canvas Version ^10.0 || ^11.0 | — | — |
orchestra/sidekick Version ^1.2 | — | — |
orchestra/testbench Version ^10.0 || ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.