This is a usable but lightly established package: it has a stable 1.0.1 release, a clear GPL-3.0 license with license files, no install-time lifecycle scripts, and only one runtime dependency. However, it is only 94 days old with two releases, has one registry maintainer, provides no packaged tests or changelog, and lacks a declared source repository, limiting transparency and preventing verification of maintenance activity. Dependence is reasonable with review and monitoring, but the package does not yet demonstrate the maturity or backing expected for a low-risk foundational dependency.
58%
Total Score
50
100
80
100
Only one account has registry publish access. This does not establish who actively maintains the project, but it does indicate a thin administrative continuity base when combined with the package's limited release history.
A substantive README is present, but the artifact has no tests or changelog and no repository evidence is available to compensate for those omissions; this weakens maintenance and release-review confidence.
The package is young at 94 days and has only two releases, with a median interval of about 94 days; this provides limited evidence of sustained maintenance and release discipline.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.