The MIT license and lack of install-time scripts reduce adoption and execution concerns. The stable version and unarchived repository help, but the one-person project and extremely small three-file tree offer limited maintenance and transparency.
38%
Total Score
25
70
75
The package has had no release in more than seven years: its latest release was April 2019, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite the three historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since its last release. No newer activity compensates for this maintenance concern.
Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader publishing or maintenance base.
The package and repository each contain only three files, including a single source file. That may fit a very small utility, but it provides little visible project structure or documentation for assessing long-term support.
The published package has no README or tests, and the repository also has neither; the GitHub release for this version is a small positive, but it does not replace consumer documentation or maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.