Consumer documentation is extremely thin, and the package has no tests or security policy. The organization-backed repository was pushed recently, but the published package itself has not been updated for nearly nine years and its repository does not identify the package.
42%
Total Score
75
63
75
The package includes a README, but it is only 17 characters long and provides virtually no integration guidance. Missing tests and changelog files are normal for a published artifact and are not concerns here.
Only two releases were published, both in December 2017, with none in the last nine years. This indicates a potentially abandoned package, although the repository was pushed recently.
The repository recorded zero commits and zero active maintainers in the last three months. The recent repository push shown by repository_archived provides some counterevidence, but not evidence of sustained maintenance.
The linked repository name does not match the package name and its README does not mention the package, so the source relationship is unclear and may complicate maintenance verification.
The repository has no security policy. That is a transparency and vulnerability-reporting gap, though it is less serious than the stale package release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.