Its BSD-3-Clause license, minimal runtime dependency, and lack of install scripts reduce adoption friction. The small source tree is understandable, but it offers little evidence of ongoing maintenance or security oversight.
42%
Total Score
100
100
64
75
The package has had no release in about 10 years: all five releases were published in December 2015, with none in the last 12 months. This is strong evidence of abandonment risk despite the package being stable.
The repository is not archived, but it was last pushed in February 2017, leaving more than 9 years without observed source activity. The non-archived status provides little compensation for this prolonged inactivity.
The artifact has no README, which is a minor transparency and integration gap for a library. Missing tests and a changelog are normal for published artifacts and do not lower the score here.
The repository has no security policy, reducing transparency about how vulnerabilities would be handled. This is a secondary concern alongside the much older maintenance signals.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.