This is a clearly identified, MIT-licensed package with a matching source repository, stable 1.2.0 release, no registry deprecation, no install-time lifecycle scripts, and a small dependency surface. However, it is only 3 days old, has just 3 releases, only 2 commits in the last 3 months, and all recent commits come from one contributor; the artifact and repository also lack tests, a changelog, and a security policy. It is reasonable for evaluation or controlled use, but its very limited history and single-maintainer activity make it less suitable for a critical dependency without additional review and monitoring.
68%
Total Score
60
100
78
90
Only one registry account has publish access. This is not a verdict on maintenance activity, but it leaves release continuity dependent on a single publisher.
A substantial README is present, but both the artifact and repository lack tests and a changelog. For a newly published SDK this is a meaningful maintenance and transparency gap, though not by itself evidence of abandonment.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance backing to offset the concentrated contributor base.
The package is only 3 days old with 3 releases, so it has insufficient release history to establish long-term maintenance reliability. The frequent early releases show activity but do not compensate for the very short observation window.
One contributor made 100% of the 2 recent commits, indicating a concentrated maintenance base and elevated continuity risk for this user-owned project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.