The artifact is very small, licensed MIT, and has no install-time scripts or dependency burden. The available project context offers little evidence of ongoing maintenance or package ownership, so pinning it creates a meaningful abandonment risk.
38%
Total Score
0
100
70
75
This package has only one release, published in February 2021, with no releases in the following five years. That is strong evidence of abandonment for a dependency intended to receive maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push in February 2021 and indicating no current maintenance activity.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that the repository is the package's authoritative source.
The repository has no security policy. For a small package this is a secondary hygiene gap, but it provides no documented channel for handling future vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.