The README, release notes, and matching repository make the package easy to inspect. Its license files conflict with the manifest, and the repository has had no commits for three months.
61%
Total Score
50
79
75
The manifest declares GPL-3.0-or-later, while an artifact license file is recognized as MIT. Although license files are present, this unresolved mismatch creates real adoption and compliance uncertainty.
The package has 12 releases and five in the last 12 months, but the latest release was about 11 months ago. That recent gap weakens confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, though the repository is not archived and was updated with the release.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a transparency gap rather than evidence of an unsafe release.
Version v0.1.3 is still below 1.0, so the public API may change and the package has less maturity evidence than a stable-major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imangazaliev/didom Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.