The small codebase has tests, no runtime dependencies, and a repository that clearly matches the package. Its license and security-policy gaps add transparency risk, while no commits or releases have appeared since April 2019.
38%
Total Score
0
100
70
50
The package is over seven years old but has only two releases, both published within about 16 hours in April 2019, with no releases in the last 12 months. This strongly suggests abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of releases since April 2019. No newer activity compensates for this maintenance gap.
Neither the package metadata nor the artifact or repository contains a recognized license. That leaves reuse and redistribution rights unclear for consumers.
The repository has no security policy. For a small, dormant package this reduces transparency about vulnerability reporting and response, though it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.