Usable with caveats: the package is licensed, documented, tested in its repository, and has a clear release note, but no release has shipped for over a year and the repository recorded no commits in the last three months. Review maintenance needs before adopting it for a core dependency.
65%
Total Score
50
100
92
67
The package has existed since 2016 with 17 releases, but it has had no release in the last 12 months and its latest release was over a year ago. This indicates slowing maintenance despite a substantial history.
The repository recorded zero commits and zero active maintainers during the last three months. That weakens evidence of ongoing maintenance, although the repository was pushed recently and the release includes documented changes.
The repository has no security policy, leaving vulnerability-reporting expectations less clear. This is a transparency gap, but it is not by itself evidence that the package is unsafe.
The only workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege declarations would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.