The package is backed by an organization, remains unarchived, and declares its licenses. Its tiny three-file artifact has no README, tests, changelog, or security policy, limiting transparency.
62%
Total Score
75
86
75
The artifact has no README, while tests and a changelog are normally repository concerns and their absence is expected here. For a plugin consumers must integrate, the missing README modestly reduces transparency.
The latest release was in August 2023, with no releases in the last 12 months. This indicates a long maintenance gap, although the package has 84 releases and is mature rather than newly abandoned.
The repository recorded no commits or active maintainers in the last three months. That supports the concern that maintenance has stalled, despite the repository not being archived.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, but it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.