This is a mature, licensed, non-deprecated package with a correctly linked repository, a stable release, a small runtime dependency footprint, and recent release and repository activity. The repository includes tests, changelog, build tooling, Dependabot, and Psalm, while the artifact’s missing tests are compensated by the source repository. The main concerns are that only one maintainer made the single commit in the last three months, the project lacks a security policy, and its workflow does not declare top-level token permissions; these are meaningful hygiene and continuity risks but do not outweigh the package’s ongoing maintenance and transparency.
79%
Total Score
63
100
100
80
The repository is owned by an individual user rather than an organization, so the concentrated recent maintenance activity is not offset by evident organizational handoff capacity.
All recent commits came from one contributor with a 100% share, creating a genuine continuity risk for a user-owned project without organizational backing.
Only one commit was made in the last three months by one active maintainer, indicating limited recent development activity and a narrow maintenance base.
No security policy was found in the repository, leaving vulnerability-reporting expectations undocumented.
The only workflow lacks top-level token permissions and does not declare read-only permissions, so its GitHub Actions permission scope is less explicit than preferred.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.