It has no license and no security policy, leaving reuse terms and vulnerability reporting unclear. The tiny repository and single-maintainer setup provide little evidence of support capacity, despite a matching source repository and simple dependency profile.
38%
Total Score
33
100
56
75
The package has only two releases, with the latest published in January 2018 and none in the last 12 months. This is strong evidence of abandonment risk for a dependency released more than eight years ago.
There were zero commits and zero active maintainers in the last three months. This directly supports a conclusion of inactive maintenance and high abandonment risk.
No declared license or license file was found, so the terms for legally using and redistributing this package are unclear.
The package and repository are owned by the same individual account rather than an organization. That is coherent ownership, but it provides limited evidence of institutional maintenance capacity.
One issue remains open, with no issues or pull requests created or closed in the last month. Combined with the stale commit history, this suggests limited ongoing responsiveness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.