The package includes a README, tests, release notes, and an MIT license, with no runtime dependencies or install scripts. Its single-person ownership and absent security policy leave little evidence of ongoing support.
39%
Total Score
25
100
70
75
The last registry release was about 10 years ago, with no releases in the past 12 months. Although the package had five releases early in its life, this long gap is a substantial maintenance risk.
The repository recorded no commits and no active maintainers in the past three months, consistent with the repository having effectively stopped receiving updates years ago.
A single registry maintainer is consistent with a small personal project, but it provides little redundancy if that maintainer becomes unavailable.
The repository has no published security policy, leaving no documented process for reporting or handling vulnerabilities. This is a hygiene and support gap rather than evidence of a vulnerability.
The assessed version is 2.0.6, while the registry reports 1.1 as the latest version, creating a material version-history inconsistency. The release is not marked prerelease, but the conflicting metadata reduces transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.