The MIT license, focused dependency set, tests, and release notes make the package straightforward to adopt. GitHub Actions use 15 unpinned references, and no security policy is published.
68%
Total Score
50
100
94
50
The package has 8 releases since December 2019, but none in the last 12 months and the latest registry release was in April 2024. This indicates a meaningful maintenance slowdown despite its established history.
The repository recorded no commits and no active maintainers in the last 3 months. The separate recent push timestamp provides some evidence of repository activity, but not of ongoing development.
The repository has no published security policy. For a library intended to be integrated into applications, this reduces transparency around vulnerability reporting.
Both workflows were fully analyzed with no detected injection or high-severity findings, but all 15 action references are unpinned. This is a supply-chain hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.