The beta label and missing security policy leave less assurance for a library, while the repository still has tests, matching ownership, and a clear license.
52%
Total Score
75
80
50
The package has had no releases in the last 12 months, and its latest release was about two years ago. Its earlier 33 releases show prior activity but do not offset the current pause.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no recent maintenance capacity.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a library dependency.
The assessed release is still a beta, and 45% of recent releases were prereleases, so compatibility and long-term support are less certain.
The only workflow uses one unpinned action, so its build dependency is not locked to a specific revision. The pull_request_target trigger has no untrusted checkout or script-injection sink, which avoids a severe workflow risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.