The small dependency surface, clear README, matching repository, and Apache-2.0 license make the package straightforward to inspect. Its lack of security tooling and very low adoption add maintenance risk; pin this legacy release rather than expecting fixes.
40%
Total Score
0
100
75
75
The latest release was on May 29, 2017, and there have been no releases in the last 12 months. The 13-release history shows an initially active project, but the roughly nine-year release gap indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but it shows no current maintenance capacity.
The repository has zero stars and forks, with only six watchers, providing little evidence of a broad user or contributor community to sustain the package.
No security policy is present in the linked repository. This is a transparency and response-process gap, especially concerning for a library that calls an external API.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.