The package is easy to inspect and has a narrow dependency footprint. Its long inactivity, tiny user base, and lack of security-policy coverage make abandonment and maintenance risk substantial.
42%
Total Score
0
100
67
75
The latest release was in April 2015, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment for a package intended as an active dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since April 2015.
The repository has zero stars and forks and only one watcher, providing little evidence of active community use or review. Popularity is supporting evidence, but this reinforces the maintenance concern.
The linked repository is not archived, which avoids an explicit abandonment marker, but its last push was still in April 2015 and does not offset the inactive commit history.
The linked repository has no security policy. This is a transparency and response-process gap, although it is less severe than the observed long-term inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.