The MIT license, matching license file, README, and release notes provide basic transparency. There are no tests or security scanning, and activity has stopped for years, limiting confidence in future fixes.
42%
Total Score
25
72
83
The package has had no release in over nine years, with only four releases overall and none in the last 12 months. This is strong evidence of abandonment for a library dependency.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.
Only one account has registry publish access, and project backing identifies an individual owner rather than an organization. This leaves limited visible maintenance capacity if that maintainer stops contributing.
The repository name matches the package, but the README does not mention the package name. The matching repository reduces the risk of an unrelated source link, while the missing README mention is a minor transparency gap.
The repository has only 2 stars and no forks or additional watchers. Popularity is not required for health, but these counts provide little supporting evidence of community use or oversight.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.