Usable with caveats: this is a very new package with only two releases and no tests, changelog, or security policy. The repository is active and the package is small and clearly linked, but its proprietary license limits confidence for an open-source dependency.
58%
Total Score
75
100
63
88
The package declares a proprietary license and provides no license file, which creates a meaningful legal and transparency concern for an open-source dependency.
A consumer-facing README is present, but the repository reports no tests or changelog; the missing tests matter for a database-backed error-handling library, while the missing changelog is normal for such a new package.
The registry namespace and repository owner are related but the repository owner is a personal account rather than an organization, so there is limited evidence of durable institutional backing.
The package is less than one day old and has only two releases, so there is little evidence of sustained maintenance or release stability.
The repository has no stars, forks, or watchers. For a package released less than one day ago this is unsurprising, but it provides no supporting evidence of adoption or external review.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.