The package has limited documentation and security-process coverage. Recent development is visible, but all five commits came from one contributor and the linked repository does not clearly identify this package.
58%
Total Score
67
75
75
The package has no README, tests, or changelog, which limits consumer guidance and verification; the GitHub release for this version is a small compensating sign of release transparency.
The repository owner is an individual user rather than an organization, so the single-contributor risk is not offset by visible organizational backing.
This is a young package, first released 39 days ago, with only one release, so there is little history to establish maturity or long-term maintenance.
All five recent commits came from one contributor, leaving the project dependent on a single active maintainer and increasing continuity risk.
The repository name does not match the package name, and no README package mention was available, so the repository's ownership of this package is unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.