The package is small and clearly documented, with a matching repository and MIT license. Its single maintainer and absent security tooling leave little visible support if issues emerge.
42%
Total Score
25
70
75
The package has only one release, published in February 2016, with no releases in roughly ten years. This is strong evidence of abandonment risk despite the stable 1.0.0 version.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the long gap since its only release. No newer activity compensates for the age of the release.
Only one registry account has publish access, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy if the maintainer is unavailable.
The repository is not archived, so it remains technically available for maintenance. However, its last push was in February 2016, which does not offset the evidence of inactivity.
The repository has no security policy, which makes reporting and handling vulnerabilities less transparent. This adds a modest maintenance concern but is not severe on its own for a small terminal-rendering library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.