The package has a clear MIT license, README, and matching source repository. Its eight-file codebase has one maintainer, no tests or security policy, and no evidence of recent project work.
38%
Total Score
25
64
67
Only two releases were published, both in August 2018, with no releases in more than eight years. This is strong evidence of abandonment for a framework dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being in 2018. No newer maintenance evidence compensates for this prolonged inactivity.
The registry lists one maintainer. The repository is owned by the same individual, so this is not merely a publishing-account artifact, but it still indicates a thin contributor base and high bus-factor risk.
The artifact and repository each contain only eight files, including four source files and no test or tooling structure. This may fit a pico-sized framework, but it leaves little evidence of maturity.
A README and release notes are present, and the package explicitly documents that it has no tests. The documentation is a modest positive, while the missing tests reduce confidence in a framework dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.