КСК
38%
Total Score
unhealthy
No releases since 2021, with a repository name mismatch and conflicting license evidence.
Only two releases exist, and none were published in about five years; this is strong evidence of abandonment risk for a package intended as a dependency.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the long release gap and lack of ongoing maintenance.
The manifest declares MIT, but the artifact license file is detected as Apache-2.0. Although a license file exists, the mismatch creates a meaningful legal and transparency concern.
A README is present, but it contains only 26 characters and the package has no tests or changelog. The missing tests and changelog are normal packaging practice; the extremely limited README weakens consumer transparency.
The linked repository name does not match the package name and its README does not mention the package, so package ownership and source provenance are unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.