The repository is small and clearly matches the package, with a readable README and no install-time scripts. A single maintainer and no security policy provide little evidence of ongoing stewardship.
43%
Total Score
25
80
75
This package has had only one release, published about 3 years and 7 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the one-release history, this indicates no observed recent maintenance.
One registry maintainer is a thin stewardship base for a package with no recent release or commit activity. The linked repository is user-owned, so there is no organizational backing shown to offset that concern.
The linked repository has no security policy. This is a transparency and response-process gap, though it is less significant than the observed maintenance stall.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.