The package is small and focused, with tests, a matching repository, and a clear MIT license. Its single maintainer, minimal adoption, and lack of security scanning reduce confidence in long-term support. Pin 1.3.0 if adopting it.
68%
Total Score
50
100
83
83
Only one registry account has publishing access, leaving limited release continuity if that maintainer becomes unavailable; the linked repository also appears user-owned rather than organization-backed.
The registry namespace and repository owner match, and the owner is a user account; this provides identity consistency but not organizational continuity.
The project has existed since 2016 with 22 releases and a release within the last year, but only one release in that period indicates modest ongoing activity.
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the lack of current development activity raises maintenance risk.
The repository has only 1 star, 1 fork, and 1 watcher, indicating minimal external adoption and a thin community safety net.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.