The MIT license, usable README, and release notes provide basic transparency, with no install-time scripts and a small dependency surface. Its maintenance outlook is poor, so pinning this release would leave you dependent on an abandoned project.
15%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on it.
This is the only release, published 832 days ago, with no releases in the last 12 months. The GitHub release notes document the initial release but do not offset the lack of subsequent maintenance.
The repository had zero commits and zero active maintainers in the last three months. Together with the archived status, this indicates no current maintenance capacity.
The linked repository is archived and was last pushed on June 17, 2024. An archived source project is a severe abandonment risk for a dependency.
The repository has no security policy. This is a transparency gap, although the stronger abandonment signals already determine the overall assessment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.