The MIT license, clear README, and single runtime dependency keep it transparent and easy to inspect. A one-person project with no tests or security policy offers little evidence of ongoing support.
43%
Total Score
50
100
83
75
Only one registry account can publish the package. The linked repository is also owned by that individual, so there is no broader organizational backing shown to offset the thin maintainer base.
The package has had no release in more than eight years: its latest release was in May 2018, with zero releases in the last 12 months. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus and leaving no evidence of current maintenance.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counts provide no visible community signal to compensate for inactivity.
The linked repository has no security policy, reducing transparency about how vulnerability reports would be handled. This adds to the maintenance concern but is not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.