It is a tiny, clearly named interface with MIT licensing and only two runtime dependencies. The organization-owned repository is intact, but lacks tests, a security policy, and pinned workflow actions.
52%
Total Score
75
100
93
75
This is the only release, published about 4 years and 5 months ago, with no releases in the last 12 months. That substantially raises abandonment risk despite the package's small scope.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity uncertain.
The repository has no security policy. This is a transparency and reporting gap, though the package's narrow interface scope limits its practical weight.
The workflow audit completed cleanly with no dangerous triggers or audit findings, but both referenced actions are unpinned. That is a modest reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
postboy/contract-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.