Its MIT licensing, single runtime dependency, README, tests, and release notes make adoption straightforward. The repository is not archived and is backed by an organization, but the lack of a security policy leaves little formal disclosure guidance.
57%
Total Score
75
100
92
50
Only two releases were published, with none in the last 12 months; the latest release was about 9 years ago. This is strong evidence of abandonment risk despite the package's stable version.
There were no commits and no active maintainers in the last 3 months, consistent with the last push being about 9 years ago. This materially raises abandonment risk.
The repository has no security policy, leaving no documented process for reporting vulnerabilities or communicating security fixes. This is a modest transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.