The small codebase has tests, a README, a matching repository, and a clear MIT license. Its alpha status and roughly 11 years without a release or commit make it a poor dependency choice.
28%
Total Score
50
100
64
75
Only one release exists, published roughly 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment despite the package remaining undeclared as deprecated.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the long release gap. This indicates no current maintenance capacity.
The assessed version is still an alpha release, and all recent releases are prereleases. The release notes explicitly say it should not be used in production, which materially limits its dependability.
The repository has only 2 stars and no forks, so there is little external adoption evidence. Popularity is supporting evidence only and does not independently determine the score.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This is a secondary transparency gap beside the much larger maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.