The package has a minimal dependency surface and a stable version, which limits integration risk. Its source repository remains identifiable and unarchived, but the project offers little evidence of ongoing care.
32%
Total Score
50
100
67
Only one release exists, published about 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last 3 months. Combined with the old last release, this indicates ongoing maintenance has effectively stopped.
The manifest says “Copyright,” but no recognized license was detected and no license file exists in either the package or repository. This creates a material adoption and redistribution concern.
The package has no README, tests, or changelog, while the repository has a README but no tests or changelog. Missing tests and changelog are normal for published artifacts, but the absent package README weakens consumer documentation for this library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.