Clear documentation, release notes, and repository tests support adoption. The single maintainer, absent security policy, and unpinned workflow actions leave limited safety margin.
60%
Total Score
50
100
83
50
One registry maintainer creates a thin publishing base, although the linked repository is owned by the same individual and the package has a matching source project.
The latest release was published on August 27, 2024, with no releases in the following 12 months; the package is established but maintenance appears inactive for about two years.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful abandonment concern despite the recent release history being otherwise coherent.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities in a package that records application activity.
The single workflow was fully analyzed with no reported audit findings or dangerous triggers, but all 3 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.