The package has only a minimal README and no security policy, limiting documentation and disclosure. Its MIT declaration conflicts with the GPL-2.0 license file, so confirm which terms apply before use.
38%
Total Score
50
50
50
The manifest declares MIT, but the detected LICENSE file is GPL-2.0. Although a license file exists, the mismatch creates a material legal and adoption risk until the applicable terms are clarified.
A changelog and GitHub release provide some release documentation, but the README is only 8 characters long and the project has no tests. The extremely limited consumer documentation is a real transparency gap for a library.
The package has had only 3 releases, all around September 2018, with no release in over 8 years. This is strong evidence of abandonment for a dependency whose compatibility may need ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving little evidence of current maintenance capacity.
The repository has no security policy. This is a hygiene and disclosure gap, though it is less significant than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.