This is a usable but very young package with strong basic transparency: it has an MIT license, a matching source repository, active recent releases and commits, no deprecation, and no observed dangerous workflow patterns or install-time scripts. The main concerns are its 22-day age, pre-1.0 version, single-maintainer and single-contributor bus factor, absence of repository tests and security scanning, and incomplete workflow permission declarations. The package appears actively developed rather than abandoned, but its limited history and concentrated maintenance make it a dependency that warrants monitoring and cautious adoption.
68%
Total Score
70
100
75
80
There is one registry maintainer, Tomas Votruba. Because the linked project is user-owned rather than organization-owned, this reflects a genuinely narrow publishing base, though repository activity provides evidence that the maintainer is active.
A substantial README documents installation, usage, and binary rebuilding, and the repository uses GitHub Releases; however, neither the artifact nor repository contains tests or a changelog. The documentation and release evidence partly compensate for the missing changelog, but the lack of tests remains a maintenance-quality gap.
The source repository is owned by the individual user TomasVotruba rather than an organization. This provides a clear owner but no organizational maintenance redundancy, consistent with the single-contributor risk.
The package is only 22 days old, although it has already had 7 releases and the latest release was published recently. The rapid release activity is encouraging but provides little long-term evidence of maintenance stability.
All 5 recent commits came from one contributor, giving the project a complete single-contributor concentration. With a user-owned repository and no second active contributor, loss of that maintainer would materially increase abandonment risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.