Usable with caveats: the package is clearly licensed, documented, tested, and backed by a matching repository, but it is brand new with no established release or commit history. A single maintainer and no security policy add uncertainty for a library with no demonstrated maintenance track record.
64%
Total Score
50
100
83
90
One registry maintainer is consistent with an individually owned project, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
The registry namespace and repository owner match, and the project is owned by an individual rather than an organization; this supports a genuine project link but offers limited institutional backing.
This is the first release and the package is zero days old, so there is no track record for release stability or long-term maintenance.
The repository has recorded zero commits and zero active maintainers in the last three months; because the package was just created, this mainly reflects limited history rather than confirmed abandonment, but it still provides no maintenance evidence.
The repository has no stars, forks, or watchers. This is weak supporting evidence rather than a standalone health failure, especially for a new package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.