The package has a valid MIT declaration and no install-time scripts, but its documentation is nearly empty and the linked repository does not identify the package. Its only release was over eight years ago, with no recent commits, leaving substantial abandonment risk.
32%
Total Score
25
64
100
This package has only one release, published over eight years ago, with no releases in the last 12 months. That strongly suggests abandonment risk, and no other signal shows ongoing maintenance.
There were no commits and no active maintainers in the last three months. Given that the only release was over eight years ago, this is strong evidence of inactive maintenance.
The package has one registry maintainer. Individual ownership is not inherently a problem, but combined with no recent release or commit activity it leaves little visible maintenance capacity.
The artifact technically includes a README, but it is only three characters long and provides no usable guidance for consumers. The absence of tests and a changelog in the published artifact is normal packaging practice.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository clearly documents and supports this package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.