Its README documents installation and use, the repository contains tests, and the package has no install-time scripts. The BSD-3-Clause licensing and narrow dependency footprint reduce adoption friction, but they do not offset the maintenance concern.
42%
Total Score
25
100
70
75
The latest release was published in February 2017, and there have been no releases in the past 12 months. This strongly indicates abandonment risk despite the package having five historical releases.
The repository has recorded no commits and no active maintainers in the past three months, with its last push in February 2017. The long period without observed development materially lowers confidence in ongoing maintenance.
Only one account has registry publish access, creating a thin publishing base. The linked repository is also owned by an individual, so no organizational backing is shown to compensate for that concentration.
The repository has one star, one fork, and one watcher, providing very little evidence of community adoption or external support. Low popularity is supporting caution rather than a verdict by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe than the maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.