The MIT license, tests, release notes, README, and minimal dependencies make adoption straightforward. Dependabot and a clean workflow audit help, but the single-maintainer project has limited redundancy.
70%
Total Score
50
100
88
75
The registry namespace and repository are owned by the same individual user, so there is no organization backing shown to compensate for the concentrated maintainer base.
The package has existed for over 12 years with eight releases, but it has had no registry release in the last year, which limits evidence of ongoing release maintenance.
All recent commits come from one contributor, leaving little demonstrated redundancy if that maintainer becomes unavailable.
There was one commit in the last three months from one active maintainer; this is evidence of some maintenance but a thin recent cadence.
No security policy is present, leaving vulnerability reporting guidance undocumented for consumers and maintainers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.