The package has a clear README, an explicit GPL-2.0 license, and only one runtime dependency. Its last registry release was about 10 years ago, repository commits have been inactive for at least three months, and six issues remain open, making maintenance uncertain.
42%
Total Score
25
100
80
50
Only two releases exist, with the latest published about 10 years ago and none in the last 12 months. This is strong evidence of abandonment risk, despite the stable version format.
The repository recorded no commits and no active maintainers in the last three months; its last push was in 2019. The long inactivity materially reduces confidence in ongoing maintenance.
Six issues and three pull requests remain open, with no new or closed issues or merged pull requests in the last month. This suggests unresolved maintenance needs, though the project is small.
The repository has no security policy and no security scanning tools. This is a transparency and response-process gap, but it is less significant than the package's long-term inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.