The package is small and easy to inspect, with a README and only one runtime dependency. Stable metadata and a matching repository add some reassurance, but the available maintenance record is too thin for a dependable dependency.
45%
Total Score
0
100
79
83
The package has had no release in more than three years, with all three releases clustered on 11 January 2023. This is strong evidence of abandonment risk despite the small package scope.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old release history, this indicates that maintenance has effectively stopped.
No license is declared, and neither the package nor the repository contains a detected license file. That leaves the legal terms for using the dependency unclear.
The repository has no security policy. This is a transparency and response-process gap, though the package's small size limits how much weight it carries.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.