It includes tests, documentation, and a clear MIT license, with no deprecation notice or install-time scripts. The linked repository does not identify this package, further reducing confidence in its provenance and maintainability.
34%
Total Score
0
100
71
75
The package has had only two releases, both in 2013, with no release in roughly 13 years. This is strong evidence of abandonment for a dependency receiving no ongoing registry updates.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and indicating no observed current maintenance.
The linked repository name does not match the package name and its README does not mention the package. Although this could reflect a packaging relationship, the available evidence does not establish that provenance clearly.
The repository has no security policy. This is a transparency and maintenance gap, though it is secondary to the much stronger evidence of inactivity.
Version v0.1.1 is below a stable major release, which increases compatibility uncertainty for consumers. The package is not marked as a prerelease, but its very early version remains a maturity concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.