It has a clear license, tests, release notes, and a matching repository. The small project has limited independent assurance, so pin this version and monitor future releases.
62%
Total Score
50
80
50
The package has only 3 releases across about 2 years and 6 months, with 1 release in the last 12 months. This indicates a slow release cadence, though it is not by itself evidence of abandonment.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That recent inactivity lowers confidence in ongoing maintenance, despite the newer repository push timestamp.
The repository has 3 stars and 1 fork, so there is little evidence of broad community adoption or external review. Low popularity is supporting caution rather than a verdict by itself.
No security policy was found in the repository. For a network client handling authentication and tokens, this leaves vulnerability-reporting expectations unclear.
Both workflows were analyzed successfully, with no untrusted checkout or script-injection path and no broad top-level write permissions. However, all 4 action references are unpinned and the high-confidence audit found a floating container image using the latest tag, creating avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rybakit/msgpack Version ^0.9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.