The package is small and clearly tied to an organization-owned repository, with a README and only one runtime extension dependency. Its missing license and lack of security tooling reduce transparency.
52%
Total Score
75
100
79
83
The package has had four releases, but none in about three years; the very short release intervals reflect an initial burst rather than ongoing maintenance.
Neither the package nor the linked repository declares or contains a detectable license, leaving the legal terms for adoption unclear.
The repository recorded no commits and had no active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has no security policy, which limits guidance for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.