A clear MIT license, tests, and a substantial README support adoption. The package has little usage evidence, no security policy, and no observed maintenance since its sole release, so pinning it carries long-term risk.
40%
Total Score
50
71
75
This is the package’s only release, published about 9 years ago, with no releases in the last 12 months. That leaves compatibility and maintenance uncertain despite the stable 1.0.0 version.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. There is no provided evidence of current development to offset this.
The repository has 2 stars, 0 forks, and 2 watchers, indicating very limited visible adoption and a small support community. Popularity is supporting evidence rather than decisive on its own, but it reinforces the maintenance concern.
The linked repository is not archived, so it remains technically available for maintenance. Its last push was about 9 years ago, however, so the unarchived status provides only limited reassurance.
No security policy is present in the repository, reducing transparency about vulnerability reporting and response. The package’s tests and documentation help consumer usability but do not compensate for this governance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.