A long project history, recent release notes, and a small runtime dependency set support continued use. The open issue backlog, absent security policy, and concentrated maintenance leave more follow-up risk than a mature team-backed project.
68%
Total Score
50
100
81
75
The artifact includes multiple license files and declares LGPL-3.0-only, but the detected license text includes GPL-3.0 as well. That declaration and detection mismatch warrants checking the intended licensing terms before distribution.
The package has existed for over 11 years with 46 releases, but only one release in the last 12 months. The latest release is recent, so this indicates slower current cadence rather than abandonment.
All two recent commits came from one contributor, giving the project a single-person maintenance dependency. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset that concentration.
Two commits were made in the last three months, showing some ongoing work, but the volume is low for a library with an active issue backlog.
There are 41 open issues, with two new issues and no issues or pull requests closed in the last month. This suggests unresolved maintenance load, although the short observation window limits its severity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.