The source includes tests, a changelog, and a usable README, but it has only one early release and no commits in the last three months. The license files also identify GPL-3.0 alongside MIT, and the repository does not clearly mention this package.
20%
Total Score
0
57
50
Packagist marks the entire package as abandoned and provides a replacement repository, making this release unsuitable as a dependable long-term dependency.
The repository has no commits and no active maintainers in the last three months, reinforcing the lack of current maintenance evidence.
The package declares MIT and includes a license file, but the detected license text includes GPL-3.0 as well as MIT; that mismatch needs clarification before adoption.
This is the only release, published 142 days ago, so there is little evidence of release maturity or an established maintenance cadence.
The repository name does not match the package name and its README does not mention this package, so the source-to-package relationship is not clearly established.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.