The package is small, easy to inspect, and has only one runtime dependency. Its lack of tests, security scanning, and a security policy leaves little evidence of ongoing quality control.
40%
Total Score
50
100
67
67
The latest release was published about nine years ago, with no releases in the last 12 months and only four releases overall. This is strong evidence of abandonment risk, although the package may be intentionally stable.
The repository is not archived, but it was last pushed about nine years ago. The non-archived status is reassuring administratively, while the lack of recent pushes still indicates likely abandonment.
One registry account has publish access. The linked repository is owned by an individual rather than an organization, so the single-maintainer setup adds some continuity risk.
The artifact and repository contain only three files, including the README, manifest, and one source file. This is consistent with a very small package, but provides little visible project structure.
The package and repository are associated with individual user accounts rather than organization backing. Combined with the single maintainer and stale repository, this provides little continuity assurance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.