The package is small and focused, with an MIT license, few runtime dependencies, and repository tests. It lacks a security policy, while its unarchived source provides some continuity but limited assurance for future compatibility.
55%
Total Score
100
67
50
The package has had no release in about 9 years, with all 5 releases concentrated on its first day. That strongly lowers confidence in ongoing maintenance, despite the package not being deprecated.
The repository has 4 stars, 0 forks, and 2 watchers, showing little external adoption or review. Popularity is supporting evidence rather than a verdict, but it offers little compensating assurance for the long inactivity.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene gap, not evidence that the package is unsafe by itself.
Version v0.1.4 is not a stable major release, so compatibility guarantees are weaker. Its non-prerelease status provides a small compensating signal, making this a minor concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.