The package has a small, focused five-file implementation and no install-time scripts. Its declared MIT license and matching repository are positives, but the sparse project documentation leaves consumers with little guidance.
40%
Total Score
50
100
63
88
The package has had only two releases, both in April 2018, with no release in more than eight years. This is strong evidence of abandonment risk for a dependency.
The package has one registry maintainer, a normal arrangement for a small user-owned project but a limited maintenance base with no organizational backing shown.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README is a documentation gap for a library consumers must integrate.
The registry namespace and repository owner match, but both identify a single user account rather than an organization, providing limited backing context.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no evidence of an active user community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.