A clear README and recent package activity make the project easier to adopt. Organization backing helps offset the single-contributor repository, though the lack of a security policy leaves less guidance for reporting problems.
62%
Total Score
67
83
75
The manifest declares a proprietary license, while the included LICENSE.txt is detected as GPL-2.0. The license file means the release is licensed, but the mismatch creates a meaningful adoption and compliance concern.
The package has six releases over about four years, with two releases in the last 12 months, but the median interval is about 304 days. This indicates deliberate but relatively slow maintenance.
All three-month commit activity comes from one contributor, creating a narrow maintenance path. Organization ownership provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months, showing limited recent development activity. The recent repository push is reassuring but does not offset the very low activity entirely.
The repository has no security policy, leaving no documented process for reporting vulnerabilities. This is a transparency gap, though it does not by itself indicate unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.