Leakless shows strong current development and reasonable package transparency: it is not deprecated or archived, has a substantial README, a matching repository, repository tests, active commits, CI workflows without the analyzed dangerous patterns, and a minimal runtime dependency profile. However, it is very young at 22 days old, remains on a 0.x release, all 38 recent commits come from one contributor, the repository has no security policy or security-scanning tooling, and two workflows lack top-level permissions while another declares write access. These factors make it usable but introduce maturity, continuity, and repository-hygiene risk for a production dependency.
68%
Total Score
70
100
78
80
Only one registry account has publish access, which is a continuity concern, although the linked repository is owned by an organization and therefore provides some institutional backing.
Seven releases in 22 days with a median interval of about 1.5 days demonstrates active iteration, but the short history provides limited evidence of long-term maintenance maturity.
All 38 recent commits were made by one contributor with a 100% share, creating a meaningful continuity risk; organization ownership offers backing but no second active contributor is shown.
The repository has active issue and pull-request activity, including seven merged pull requests in the last month, but seven newly opened issues versus two closed issues leaves an unresolved backlog.
The repository has only 1 star and no forks or watchers. This is weak supporting evidence, but popularity alone does not establish that a small package is unhealthy.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.