The package has a clear README, a minimal dependency footprint, and no install-time scripts. Its license mismatch and repository documentation gap reduce transparency alongside the long-maintenance pause.
43%
Total Score
0
100
58
100
The latest recorded release was in June 2017, with no releases in the last 12 months; this indicates a project that has seen no recent maintenance for about 9 years.
The repository had no commits and no active maintainers in the last 3 months, and its last push was in June 2017; this supports the conclusion that maintenance has stopped.
The manifest declares the package proprietary, while the repository contains an MIT license file. The repository license provides a usable licensing basis, but the mismatch reduces transparency for consumers.
The repository name matches the package, but the README does not mention the package name. That is a modest transparency gap, though the matching repository name partly compensates for it.
The assessed version is 1.2.2, while the signal reports 1.1.3 as the latest version, creating a release metadata inconsistency that weakens confidence in the package history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.