Risky to adopt: the package has had no release or repository activity since October 2020, and the repository has no tests or security policy. It is correctly licensed and not deprecated or archived, but the long period without maintenance makes abandonment a significant concern.
42%
Total Score
0
75
75
The latest release was published in October 2020, with no releases in the last 12 months. Nearly six years without a release is strong evidence of an inactive project, despite its seven-release history.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package's long release gap and indicating no current maintenance capacity.
The artifact includes a README, but it is only 11 characters long, and the source repository reports no tests or changelog. For a small library this is not automatically disqualifying, but it leaves limited evidence of quality or ongoing project practices.
The linked repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no community signal to offset the lack of recent maintenance.
No security policy was found. This is a transparency gap for a WebSocket client library, especially when there is no recent activity showing that vulnerabilities would be handled elsewhere.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.