The repository is not archived, the package has a matching Apache-2.0 license, and it has no install-time scripts. Consumer documentation is absent, and the repository does not clearly match the package name. Pin this version only when maintaining an existing integration.
38%
Total Score
0
100
67
100
This package has only one release, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, despite the stable version designation.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No provided maintenance signal compensates for this inactivity.
The published artifact has no README, while this is a library that consumers may need to integrate; the repository also reports no tests or changelog. The exact version does have a GitHub release, which provides some release traceability.
The linked repository name does not match the package name, and no README package mention was found. That makes the source-to-package relationship less transparent, although it may still be a legitimate differently named repository.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.