Documentation, licensing, tests, and release notes are in place, with only one runtime dependency. Its source has not changed since June 2018, and the prerelease remains without recent releases or a security policy.
43%
Total Score
50
100
75
50
The package has had only four releases, with none in the last 12 months, and the latest release was in June 2018. This is strong evidence of abandonment risk despite the package's age and prior release cadence.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive since 2018. This materially increases the risk that issues and compatibility problems will go unaddressed.
The repository has no security policy. For an old dependency this reduces transparency about how vulnerabilities should be reported and handled.
The assessed version is still a prerelease, and all recent releases were prereleases. That limits maturity and signals that the public API may not be settled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.