It includes a README and changelog, and the repository matches the package. Only two releases exist, both from the initial day, with no commits for about two years. No license is declared or included, which creates a clear adoption and redistribution problem.
42%
Total Score
0
79
75
The repository recorded zero commits and zero active maintainers in the last three months, while the latest push was about two years ago. The inactive history is a meaningful abandonment concern.
No declared license, license file, or repository license file was detected. This leaves developers without clear permission to use, modify, or redistribute the package.
The package has only two releases, both published on the same day, and none in the last 12 months. This indicates limited maturity and no demonstrated ongoing maintenance.
The repository has no security policy. This is a transparency and reporting gap, though the small package scope and lack of other collected security warnings keep it from being a severe risk by itself.
The latest version is v0.0.2 and is not a stable major release, so the API may still change substantially. The lack of later releases reinforces that this is an unfinished project rather than an actively evolving one.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.