The package is small and clearly documented, with a matching source repository and a permissive license. However, its maintenance record is effectively dormant, so adopting it creates a substantial abandonment risk.
40%
Total Score
50
67
83
The latest release was published in April 2014, and there have been no releases in the last 12 months. This long period without published updates is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No newer maintenance activity is visible to offset that concern.
The repository has 0 stars, 1 fork, and 1 watcher, providing little evidence of a broad user or maintainer community. Low popularity alone is not disqualifying, but it does not compensate for the dormant maintenance record.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though the package's small scope limits its weight.
The assessed version is a non-prerelease 0.4.0 release, but the package remains below 1.0 after a very old release history. The stable release marker offers limited reassurance against its age and inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.