Clear documentation, a license, repository tests, and release notes make the package easy to evaluate and integrate. Its single maintainer and unpinned workflow actions add modest operational risk.
67%
Total Score
50
100
94
75
Only one registry maintainer is listed. The linked repository is user-owned rather than organization-backed, so the small maintainer base leaves limited visible publishing redundancy.
The project has existed since 2017 with 16 releases, but it has had no registry release in the last 12 months and the latest release was in December 2024, indicating slowed maintenance.
There were no commits and no active maintainers in the last 3 months, a concrete sign of currently quiet development that reinforces the release-history concern.
No security policy is present in the repository. This is a transparency gap, though Dependabot provides some compensating security maintenance.
The sole workflow was fully analyzed with no injection or high-severity findings, but all 6 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.