The project has strong basic documentation, tests, a changelog, and a matching source repository. Maintenance has stopped for about three months, and all three workflow actions are unpinned; the missing security policy adds a smaller transparency concern.
62%
Total Score
75
100
88
50
The package published nine releases over about one month, showing active early development, but no release has appeared since June 4, roughly three months ago. This supports a cautious rather than healthy maintenance assessment.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. The clean tracker is positive, but the absence of activity offers little evidence of ongoing maintenance.
The repository has no security policy. For a package that processes markup and is intended for application use, the absence of a documented vulnerability-reporting path is a modest transparency gap.
Version v0.2.2 is not a prerelease, but the package remains below a stable major version. That indicates a still-evolving API and adds modest adoption risk.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, leaving build inputs less reproducible and increasing supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atk14/xmole Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.