MIT licensing, a clear README, and a single runtime dependency keep integration simple. Maintenance is the concern: no release or repository commit activity for over two years, with no tests or security policy.
58%
Total Score
50
100
83
83
One registry maintainer is consistent with the individual-owned repository, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
The package and repository are owned by the same individual account, so the source link is coherent. There is no organizational backing shown to compensate for the thin maintainer base.
The latest release was published on January 8, 2024, and there have been no releases in over two years. The earlier seven-release history shows initial activity but does not offset the current pause.
There were zero commits and zero active maintainers in the last three months, and the repository has not been pushed for over two years. This is a meaningful abandonment risk.
There was no issue or pull-request activity in the last month. The absence of open work is mildly positive, but combined with the lack of commits it provides no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.