This release appears healthy and suitable to depend on: it has a stable major version, six releases in the last 12 months, active recent repository work, tests, changelog, security policy, dependency scanning, and a clean workflow risk profile. The main concerns are that all 30 recent commits come from one contributor and both workflows lack top-level token permissions, which reduce resilience and hardening but do not outweigh the strong maintenance and transparency evidence. Popularity is very low, though that is supporting evidence rather than a decisive health problem.
84%
Total Score
70
100
94
90
Only one registry maintainer is listed. This is a resilience concern for an individually owned project, although the active repository evidence partly compensates for the narrow publishing base.
The repository is owned by an individual user rather than an organization, so the single-contributor and single-registry-maintainer concentration is not offset by visible organizational backing.
One contributor made all 30 commits in the last 3 months, creating a clear single-maintainer continuity risk with no second active contributor shown.
The repository has only 2 stars, 0 forks, and 1 watcher. This indicates limited external adoption or review, but popularity is supporting evidence and does not outweigh the package's active development.
Both workflows lack top-level token permissions, and one relies on job-level permissions only; explicit least-privilege declarations would improve CI hardening.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.