The long project history, readable documentation, and extensive test suite provide useful support. Recent activity is quiet, the project has no security policy, and the declared Apache-2.0 license conflicts with the detected BSD-2-Clause license.
65%
Total Score
50
79
75
The artifact declares Apache-2.0 but its license file is detected as BSD-2-Clause, while repository license files exist. The release is licensed, but the mismatch creates avoidable legal uncertainty.
The package has existed since 2015 with 34 releases, but only one release appeared in the last 12 months despite a historical median interval of about 10 days. This suggests materially slower recent maintenance.
No commits and no active maintainers were recorded in the past three months. The recent release and latest push provide some counterweight, but the current maintenance signal is weak.
The repository has no published security policy. This is a transparency gap for a maintained library, although the presence of GitGuardian scanning provides limited compensating evidence.
Version 0.9.8 is not marked as a prerelease, and recent releases contain no prerelease versions. Remaining below 1.0 signals a less settled compatibility contract, but does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.