The package includes tests, release notes, a clear license, and an organization-backed repository. Workflow references are unpinned and the repository has no security policy, so ongoing maintenance and build hygiene remain weaker than the package structure suggests.
62%
Total Score
75
100
86
75
The package has only 5 releases since November 2021, with no registry release in the last 12 months; the latest release was about 17 months ago. This indicates slow delivery and raises maintenance concerns.
No commits or active maintainers were recorded in the last 3 months. This weakens evidence of ongoing maintenance, even though the repository has a recent push timestamp.
No security policy is present in the repository. For a library intended to parse and encode configuration data, this is a transparency gap, though it is not evidence of a security defect by itself.
Version v0.1.4 is not a stable major release, so the public API may still change. It is not marked prerelease, which partly offsets the concern.
All 8 analyzed action references are unpinned, which weakens build reproducibility. One workflow has top-level write permissions, but the audit found no untrusted checkout, script injection, or other high-confidence dangerous finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
toolkit/stdlib Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.