Its MIT license, tiny runtime dependency set, and matching source repository keep it transparent. The project lacks recent maintenance and a security policy, making long-term support unlikely.
18%
Total Score
0
100
58
50
The package includes a README and a GitHub release, but its own README explicitly marks it as deprecated and recommends Nova's built-in feature instead. The absence of tests and a changelog is normal for a published artifact and is not itself a concern.
The latest release was in November 2018, with no releases in the last 12 months. That long release gap strongly indicates abandonment for a dependency intended to remain supportable.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases.
The repository is not formally archived, although its last push was in November 2018. The separate commit and release history signals show that it is effectively inactive.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities. This compounds the maintenance concern but is less significant than the absence of recent releases and commits.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.