The single-maintainer project lacks a security policy, while its MIT licensing, documentation, and small dependency footprint are clear. Pin this only when accepting the risk of an aging library.
43%
Total Score
38
100
72
83
The package has had no release in over five years: its latest release was January 2021, with zero releases in the last 12 months. This is strong evidence of abandonment for a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, indicating that maintenance has effectively stopped.
Only one registry account has publish access, leaving a thin publishing base. This is a modest concern, especially alongside the inactive repository, though access records alone do not establish maintenance activity.
The repository is owned by an individual user rather than an organization, so there is no organizational backing signal to offset the thin maintainer base or inactive history.
There have been no new or closed issues or pull requests in the last month, and no pull requests were opened or merged. This supports the broader picture of little current project activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.