Healthy and suitable to depend on. It has frequent recent releases, active work from four contributors, and an organization-backed repository, with only a repository/package naming mismatch and modest security-policy hygiene gaps.
88%
Total Score
100
100
94
80
The repository name does not match the package name and its README does not mention the package. Although the repository URL is plausibly related, the missing explicit package reference weakens provenance transparency.
No security policy is present in the repository. This is a transparency gap for reporting vulnerabilities, although active maintenance and security tooling provide some compensation.
The only workflow does not declare top-level token permissions, so its required access is less explicit than preferred. No top-level write permissions were observed, limiting the practical concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.