The package has clear documentation, a license, and recent commits. Its single-contributor project, very short release history, and repository/package mismatch leave meaningful maintenance and ownership uncertainty.
57%
Total Score
67
70
50
The repository is owned by an individual rather than an organization, so the concentrated contributor activity is not supported by visible organizational maintenance capacity.
The package is only 38 days old with two releases, so there is limited evidence of sustained maintenance or release discipline.
One contributor made all nine recent commits, leaving no demonstrated backup maintainer if that person stops maintaining the project.
The repository name does not match the package name and its README does not mention the package, so the source-package relationship is not clearly established.
The repository has no security policy, reducing transparency about how dependency and vulnerability reports would be handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.