The small, dependency-free codebase is clearly documented and includes tests, limiting maintenance complexity. Its lone registry maintainer, absent security policy, and long-standing lack of activity leave little evidence of ongoing support.
42%
Total Score
38
100
75
83
The latest release was published in October 2016, and there have been no releases in the last 12 months despite the package being over 10 years old. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no current maintenance.
Only one account has registry publishing access. That can be adequate for a small package, but it leaves limited visible publishing capacity when combined with the absence of recent releases.
The repository is owned by an individual user rather than an organization, so the single-maintainer context is not offset by visible organizational backing.
There is one open issue, with no new or closed issues or pull requests in the last month. The small issue count is not itself severe, but the lack of activity reinforces the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.