A clear README, matching repository, and MIT license make integration and ownership transparent. The release has had no registry releases or repository commits for nearly three years, with one maintainer and no security policy.
58%
Total Score
50
86
75
Only one registry maintainer is listed, leaving publishing and maintenance dependent on a single person. The matching repository provides ownership evidence but does not offset the thin maintainer base.
The package has 8 releases since September 2021, but none in the last 12 months; its latest release was in October 2023, nearly three years ago. This is a meaningful maintenance concern despite the stable release history.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release gap. This raises abandonment risk.
The repository has zero stars and forks and only one watcher, so there is little visible community support to help detect or address maintenance problems. Popularity is supporting evidence rather than a verdict.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a hygiene and maintenance gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.