The small codebase and exact-version release notes help explain what is being installed. However, the package has had no release or commit activity for nearly six years, provides no license, and its repository name does not match the package.
35%
Total Score
0
56
50
The last release was nearly six years ago, with no releases in the past 12 months; this is strong evidence of abandonment risk despite six total releases.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the nearly six-year release gap and indicating no current maintenance capacity.
No license is declared, detected, or present in the package or repository, leaving the legal terms for using this dependency unclear.
The package lacks a README and tests, but the exact version has GitHub release notes and the absence of tests or a changelog in the artifact is normal packaging practice.
The linked repository name does not match the package name, and no README reference was available; this creates uncertainty about whether the repository is the package's intended source.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.