compare SPDX license expressions
58%
Total Score
caution
Usable with caveats: no releases since March 2018 and no recent commits.
The package has only 3 releases and none in the last 12 months; its latest registry release was over 8 years ago, which materially raises abandonment risk.
The release has no build attestation or trusted-publisher metadata, so consumers cannot verify how the published artifact was produced. This lowers supply-chain transparency but is not severe on its own.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, providing no evidence of current maintenance despite the repository not being archived.
With 3 stars, 4 forks, and 1 watcher, the project has limited community visibility. Popularity is supporting evidence only, so this modestly reduces confidence rather than determining the verdict.
The repository reports no build tools and no security-scanning tools. This is a transparency and maintenance-hygiene gap, though the package is small and has no install-time lifecycle scripts.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spdx-ranges Version ^2.0.0 | — | — |
array-find-index Version ^1.0.2 | — | — |
spdx-expression-parse Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.