This is a healthy, actively maintained release with a consistent release cadence, a stable non-prerelease version, recent repository activity from four maintainers, organizational backing, tests, a clear MIT license, and no deprecation or install-time lifecycle scripts. The main concerns are incomplete repository security hygiene: no security policy, several workflows without top-level token permissions, and one workflow with top-level write permissions. Repository popularity is low, but the active maintenance and organizational ownership provide stronger evidence of dependency health than popularity counters; the absent changelog is also mitigated by GitHub Releases and regular publishing.
88%
Total Score
100
100
94
80
The repository has 0 stars and 0 forks, indicating limited public adoption evidence; this is only a supporting concern because recent commits, releases, and organizational backing demonstrate active maintenance.
The repository has no security policy, leaving vulnerability-reporting guidance and disclosure expectations unspecified.
Three of four workflows lack top-level token permissions and one workflow declares top-level write permissions, which is weaker least-privilege hygiene even though no dangerous workflow behavior was detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.