The package includes tests, release notes, a clear README, and no runtime dependencies. Workflow references are entirely unpinned, and recent commit activity is limited to one contributor, which weakens maintenance confidence.
58%
Total Score
67
100
94
50
A post-install command runs during installation, adding execution behavior to dependency setup. Its presence alone does not show harmful or excessive behavior, so this is a limited hygiene concern.
Only two releases were published, with the latest in September 2022 and none in the last four years. The repository remains active, but the registry release history shows limited release maturity and stale distribution activity.
All recent commits came from one contributor, creating a concentrated maintenance path. Organization ownership provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
Only one commit was recorded in the last three months, with one active maintainer. This indicates thin recent maintenance even though issue and pull-request activity remains visible.
The repository has no documented security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.