Usable with caveats: the package is licensed, documented, linked to an active-looking repository, and has repository tests and release notes. However, it has had no registry release in about one year and no commits in the last three months, so maintenance may be slowing.
60%
Total Score
63
100
94
80
One of five workflows contains a detected script-injection pattern, creating a concrete CI security-hygiene concern even though no dangerous pull-request-target or untrusted-checkout workflow was found.
Only one registry account has publish access, and the repository is owned by a user rather than an organization. This creates some bus-factor and release-continuity risk for a package with no recent releases.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization, so there is limited evidence of institutional backing.
The package has 18 releases since September 2024, but none in the last 12 months and the latest release was about one year ago, which raises maintenance concerns.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the concern that maintenance has slowed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zero-to-prod/data-model Version ^81.0 | — | — |
zero-to-prod/dynamic-setter Version ^71.0 | — | — |
zero-to-prod/package-helper Version ^1.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.