The small, tested codebase has clear licensing and matching repository ownership. Its last release and repository activity are from 2017, so maintenance and compatibility risk are substantial.
42%
Total Score
50
100
67
50
The package has only two releases, both in February 2017, with no release in roughly 9 years. That is strong evidence of abandonment for a library dependency.
The repository recorded no commits and no active maintainers in the last 3 months, while its latest push was in 2017. This leaves little evidence of ongoing maintenance.
The repository has 0 stars and 0 forks, providing little supporting evidence of community adoption or external review. Popularity is only supporting evidence, so this reinforces rather than drives the maintenance concern.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was in March 2017 and does not offset the inactive commit history.
The repository has no security policy. This is a transparency and incident-handling gap, although the small codebase and lack of recent activity limit how much weight it carries.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.