The package is small, dependency-light, clearly documented, and backed by repository tests and release notes. Maintenance rests with one active contributor, while workflow actions are entirely unpinned and lack a security policy, leaving limited long-term and build-integrity margin.
68%
Total Score
50
100
88
75
The package and repository are owned by the same individual account, confirming ownership alignment but providing no organizational maintenance coverage.
The package is young, with three releases over about eight months and a median interval of roughly 104 days. That shows ongoing publishing but offers limited evidence of long-term maintenance.
One contributor made 100% of the last three months' commits. Because the repository is user-owned rather than organization-backed, this concentration is a meaningful continuity risk.
Only two commits were made in the last three months, all by one maintainer. Recent activity exists, but the narrow and light cadence limits confidence in sustained maintenance.
No repository security policy is present. This is a transparency gap for reporting vulnerabilities, though the small, dependency-free runtime surface partly limits its practical impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.