The release is stable and the package matches its linked repository. Its tiny 22-file project has only a 75-character README, no security policy, and no license. Pin v1.0.1 only if you can accept its lack of maintenance and licensing clarity.
43%
Total Score
25
61
75
No declared license, license file, or repository license file was detected. That creates a substantial adoption and redistribution concern.
The package has only two releases, both in May 2023, and none in about three years. This strongly suggests abandonment risk for a framework dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no recent releases.
Only one registry maintainer is listed. The linked repository is user-owned rather than organization-backed, so there is little visible maintainer redundancy.
The package includes a README and has a GitHub release for this version, but the README is only 75 characters and provides minimal integration guidance. Missing tests and changelog files are normal for a published artifact and are not counted against it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.