Documentation, tests, and a clean dependency profile make the package easy to inspect. The license mismatch and absent security policy add transparency concerns alongside its limited maintenance activity.
45%
Total Score
63
100
72
75
The package has had only two releases, both on February 10, 2023, and none in the last three years. This strongly suggests abandonment risk despite the stable version format.
There were zero commits and zero active maintainers in the last three months, consistent with a project whose last recorded activity was over three years ago.
A license file is present, but it identifies Apache-2.0 while the manifest declares MIT. The package is licensed, yet the disagreement creates avoidable legal and transparency uncertainty.
There are no open issues or pull requests and no recent activity. This is not inherently negative, but it provides no evidence of an active support or improvement cycle.
The repository has one star, zero forks, and one watcher. Low adoption is supporting evidence of limited maturity and community review, though popularity alone is not decisive.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.