The package is small and clearly structured, with tests, a README, MIT licensing, and no install-time scripts. Its last release and repository activity were over eight years ago, while one person controls publishing, leaving little evidence of ongoing support.
45%
Total Score
38
61
83
The latest release was over eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having three historical releases.
There were no commits and no active maintainers in the last three months, consistent with the repository having been inactive for over eight years.
The repository is not archived, but its last push was over eight years ago; the non-archived status does not compensate for the prolonged inactivity.
Only one registry account has publishing access, leaving a thin publishing base and increasing continuity risk for an already inactive package.
The package and repository are owned by the same individual account, so there is no organizational backing shown to offset the single-maintainer risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.