The license declaration conflicts with the GPL-3.0 license file, and the linked repository does not identify this package. Its small artifact has a stable version and no install scripts, but maintenance evidence is stale.
38%
Total Score
50
50
50
The manifest declares MIT while the artifact license file is detected as GPL-3.0. A license file exists, but this mismatch creates material uncertainty about the terms consumers may rely on.
The package has had no release in the last 12 months, and its latest release was about 3 years and 9 months ago. Eight releases show some history, but the long inactivity materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's stale release history. The repository is not archived, but it shows no recent maintenance.
The linked repository name does not match the package name, and no README package mention was found. A monorepo sub-package could explain a name mismatch, but the available evidence does not establish that relationship.
The linked repository has no security policy. This is a transparency gap, though the package's small scope and lack of other observed security-process evidence limit how strongly it affects the assessment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.