Usable with caveats: the package is clearly identified, licensed, tested, and has a stable release, but it has seen no release or repository activity for about eight years. Its very small public footprint and lack of a security policy increase maintenance risk for new dependencies.
58%
Total Score
50
100
78
90
There were no commits or active maintainers during the last three months, consistent with roughly eight years since the last repository push and indicating a strong abandonment risk.
Only one registry publishing account is listed, which is a limited operational base; however, the organization-owned repository provides some backing and makes a short registry list less concerning.
The package has 14 releases since March 2015, but its latest release was in January 2018 and there were no releases in the last 12 months. That long release gap is a meaningful maintenance concern.
There are no open issues or pull requests and no recent issue activity; this is neutral rather than positive because it may reflect the repository's very small and inactive community.
The repository has only 1 star and 1 fork, indicating a very small public adoption and support footprint. Popularity is supporting evidence rather than a standalone verdict, but it reinforces the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.