The small, tested artifact has clear licensing and a repository that matches the package. Its single-maintainer project has had no commits or releases for about five years, leaving substantial maintenance risk.
45%
Total Score
33
100
86
83
The package has had six releases, but none in the last five years and no release activity in the past 12 months, indicating likely abandonment.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and leaving maintenance concerns unresolved.
One registry maintainer is responsible for publishing the package, creating a thin continuity base when combined with the absence of recent repository activity.
There were no new or closed issues or pull requests in the last month. This is not harmful by itself, but it provides no evidence of ongoing support alongside the stale commit history.
The repository has no security policy. For this small package that is a minor transparency gap, but the project also lacks recent activity to compensate for it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.