The package is small, clearly licensed, and accurately linked to its source repository, with no install-time scripts. Its single-maintainer project has had no release for about 6 years and no commit activity for about 4 years, while security guidance is absent.
45%
Total Score
25
67
75
Only two releases exist, with none in the last 12 months; the latest was published in August 2019, about 6 years ago. This is strong evidence of an unattended dependency, despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was in January 2022. That long period without observed development raises abandonment risk.
One registry maintainer is responsible for publishing the package. This is a thin operational base, though the linked repository is owned by the same individual and the package is a small focused extension.
The repository has no security policy or documented security-reporting path. This is a transparency gap, although the package's small scope limits how much weight it carries relative to the stale maintenance signals.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.