Clear licensing, a substantial 933-file artifact, and no install-time scripts reduce immediate adoption friction. There is no repository security policy or automated security scanning, while the linked project shows no recent issue or pull-request activity.
38%
Total Score
38
83
75
The package has had only two releases, with none in the last 12 months; its latest release was over 10 years ago. This is strong evidence of abandonment risk despite the package being mature and stable.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was over 10 years ago. No provided signal shows compensating current maintenance.
Only one registry account has publish access, leaving the release channel dependent on a very thin publishing base. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader continuity.
The linked repository is owned by a user account, not an organization, and the registry namespace matches that user. This does not invalidate the package, but it provides limited evidence of durable project backing.
There were no new or closed issues and no pull-request activity in the last month. This reinforces the broader evidence that the project is inactive, although the lack of open issues is not itself a health benefit here.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.