Risky to adopt: this is a usable static-asset package, but it has had only one release and no repository commits for nearly 13 years. The missing license and repository README reference also make long-term ownership and reuse less transparent.
42%
Total Score
0
67
100
The package has only one release, published nearly 13 years ago, with no releases in the last 12 months. That is strong evidence of a frozen project, although static assets can sometimes be intentionally version-pinned.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was nearly 13 years ago. No provided signal shows ongoing maintenance to compensate for this inactivity.
No declared license or license file was found in the package or repository. For a package distributing JavaScript assets, that creates a material reuse and dependency risk.
The repository name matches the package, but its README does not mention the package. This weakens transparency about how the registry release relates to the source repository.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.