MIT licensing, a clear README, repository tests, and recent security tooling improve transparency. The organization-backed repository is active, but the package's limited release history leaves its long-term maintenance unproven.
68%
Total Score
83
83
50
This package is only 26 days old and has one release, so there is not enough history to establish dependable maintenance or release continuity.
All four recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization ownership provides some handoff capacity but no second active contributor is shown.
The v0.1.0 release is not a stable major version, and the README explicitly says the public API is still being prepared, which raises compatibility risk for adopters.
The single analyzed workflow has read-only permissions and no reported dangerous findings, but its only action reference is unpinned, leaving avoidable build-reproducibility and action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.