Release activity is established, with six releases in the last 12 months and a documented fix for this version. The source project has tests, recent repository pushes, and dependency scanning, but its workflow permissions and bot check need tightening.
55%
Total Score
75
100
88
67
The registry marks the entire package as abandoned, which is a substantial adoption concern even though the listed replacement is the same package and the source remains active.
No commits or active maintainers were recorded in the three months before collection, which weakens the otherwise positive release history and suggests a recent slowdown.
The repository has no published security policy, leaving vulnerability reporting and handling less transparent for an API client.
The only workflow uses a pull_request_target trigger, grants top-level write permissions, leaves its action unpinned, and has a high-confidence bot-conditions finding; although no untrusted checkout or script injection was found, this is meaningful workflow hygiene risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.