The package includes tests, a changelog, clear licensing, and a small runtime dependency surface. Its single-user ownership and lack of a security policy or scanning provide limited assurance for future changes.
54%
Total Score
33
100
63
75
The package has only 3 releases and none in the last 12 months; its latest release was over five years ago. This indicates substantial abandonment risk despite the package remaining registered.
There were no commits and no active maintainers in the last three months, with the repository's last push over five years ago. This is the strongest indication that maintenance has stopped.
Only one registry maintainer account is listed. Because the repository is also user-owned rather than organization-backed, there is little redundancy if that maintainer stops publishing.
The registry namespace and repository are owned by the same individual account rather than an organization. This is consistent ownership, but it provides less visible backing capacity than an established organization.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these numbers provide no community signal to compensate for the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.