The project is brand new, with only two releases and no recorded commits in the last three months, so maintenance capacity is unproven. Its license, repository tests, dependency tooling, and matching source repository provide useful transparency, while unpinned workflow actions remain a minor hygiene concern.
62%
Total Score
75
100
89
83
The package is 0 days old with only two releases, so there is not enough release history to establish sustained maintenance. This is a meaningful maturity gap rather than evidence of abandonment by itself.
No commits or active maintainers were recorded in the last three months. Because the repository is newly created, this mainly shows that sustained maintenance is unproven rather than that an established project has gone dormant.
The repository has zero stars, forks, and watchers. For a package released only minutes earlier this is expected, but it offers no independent evidence of maturity or community support.
The repository has no security policy. This is a transparency gap for an audit-logging library, although it is not by itself evidence that the release is unsafe.
The single workflow was fully analyzed and has no detected dangerous sinks or audit findings, but both of its action references are unpinned. That leaves avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.