The single-user project has no tests, changelog, README, or security policy, limiting confidence for a library. Its tiny dependency footprint and matching repository keep the risk bounded.
55%
Total Score
50
100
72
83
There were no commits and no active maintainers in the last three months, consistent with the repository having last been pushed about 13 months ago. This is the strongest maintenance concern.
One registry account publishes the package. That is a limited publishing base for a user-owned project, but it is consistent with the matching repository ownership and is not by itself evidence of poor health.
The published artifact has no README, tests, or changelog, and the repository also reports none. Missing tests and changelog are normal for a published artifact, but the absent README reduces integration transparency for this library.
The package has only three releases, all within about 10 days, followed by no release in the last 12 months. That suggests maintenance has stopped, though the project may be small and complete.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation modestly without determining the verdict.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.