Usable with caveats: the repository is active, documented, tested, and not archived, but registry releases have stopped and all recent commits come from one contributor. Review the release gap and maintainer concentration before making it a critical dependency.
68%
Total Score
50
94
80
One of five analyzed workflows contains a script-injection pattern, creating a workflow hygiene concern even though no pull-request-target or untrusted-checkout workflow was detected.
The package and repository share the zero-to-prod namespace, but the repository owner is an individual account rather than an organization, so there is no organizational handoff capacity to offset the narrow maintainer base.
The package has 64 releases over roughly two years, but it has had no registry release in the last 12 months despite the repository receiving a recent push; this is a meaningful maintenance concern.
One contributor made all three commits in the last three months, leaving maintenance dependent on a single active person and increasing abandonment risk.
The repository recorded three commits in the last three months, showing some ongoing activity, but the volume is modest and does not fully offset the lack of recent registry releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zero-to-prod/package-helper Version ^1.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.