The package offers little consumer documentation and no automated security scanning. Its stable version and non-deprecated registry status are modest positives, but they do not offset the transparency gaps.
38%
Total Score
38
67
83
Only three releases were published, all around the initial release in October 2021, with no releases in the last 12 months. This strongly indicates an abandoned or inactive release line.
There were no commits and no active maintainers in the last three months, consistent with the release history showing no updates for nearly five years. This is strong evidence of abandonment risk.
No license declaration or license file was detected in either the package or repository. That creates a material legal and transparency concern for dependency adoption.
Only one registry maintainer is listed, so publishing continuity depends on a single person. The repository is also owned by an individual rather than an organization, providing no visible organizational redundancy.
The artifact has no README, leaving consumers without package-level usage guidance. Missing tests and a changelog are normal for published artifacts and are not concerns here.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.