Usable with caveats: this is a very new library with only one release and no commits recorded in the last three months, so its maintenance track record is unproven. The linked organization repository has tests, automated dependency updates, a matching README, and no risky workflow patterns, which provides some support for adoption.
68%
Total Score
83
100
88
80
The published artifact has no README, which is a consumer-facing documentation gap for a configuration library, but the source repository does contain a README and tests.
The package is only 2 days old and has a single release, so there is not enough release history to demonstrate sustained maintenance or compatibility stability.
No commits and no active maintainers were recorded in the last three months. Because the repository is only 2 days old, this is more an unproven maintenance record than evidence of abandonment, but it remains a meaningful caveat.
The repository has no security policy, leaving disclosure and response expectations undocumented for a library that may handle application configuration.
The single workflow does not declare top-level token permissions. Although it declares no top-level write access, explicit least-privilege permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.