The README, tests, MIT license, and release notes make adoption straightforward. Maintenance evidence is weak, and the linked repository does not clearly identify this package; pin carefully or prefer an actively maintained alternative.
52%
Total Score
50
100
83
75
Only two releases exist, with none in the last 12 months; the latest release was published over three years ago. This points to limited ongoing maintenance, despite the package not being deprecated.
The repository had no commits and no active maintainers in the last three months. That weakens evidence of current maintenance, although the repository is not archived.
The linked repository name does not match the package name and its README does not mention the package. This creates uncertainty that the repository is the package's actual source.
The repository has no security policy. For a small validation library this is a transparency gap, but it is secondary to the stronger maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.