A single contributor made two recent commits, but all three workflow dependencies are unpinned and the repository has no security policy. Tests, Dependabot, matching source, and a clear MIT license provide useful safeguards.
62%
Total Score
50
86
67
The registry namespace and repository are owned by the same individual account, rather than an organization with evident handoff capacity. This is consistent with the single-contributor continuity risk.
Only two releases exist, both published about two years ago, with no release in the last 12 months. This is a meaningful maintenance concern for a library, despite recent repository pushes suggesting limited ongoing work.
All recent commits came from one contributor, giving the project a complete single-person bus factor. That increases continuity risk for a small, user-facing library.
Two commits were made in the last three months by one active maintainer. This is positive evidence against abandonment, but the activity is limited.
The repository has no security policy. This limits transparency about vulnerability reporting and handling, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.