MIT licensing and a single runtime dependency reduce adoption friction. The very small codebase has limited validation and no visible security process, while long-term inactivity makes maintenance support unlikely.
32%
Total Score
0
100
67
83
The package has had only two releases, both in October 2017, and none in the last 12 months despite being more than eight years old. This is strong evidence of abandonment rather than merely a slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was in October 2017. That leaves no recent evidence of maintenance capacity.
The package includes a README and changelog, which provide basic consumer and release context, but it has no tests and the README is only 213 characters. For a transaction-handling library, that offers little validation or integration guidance.
The repository name does not match the package name and its README does not mention the package. This raises uncertainty about whether the linked repository is the package's actual project home.
The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or community review. Popularity is only supporting evidence, but its absence reinforces the maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.