The package is small and easy to inspect, with a short README, one runtime dependency, and no install hooks. Its MIT declaration and matching repository help, but the single-person project has no security policy or security scanning.
38%
Total Score
50
100
80
83
Only one registry maintainer is listed, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is little shown capacity to cover maintainer absence.
The package has had no release in the last four years, despite five releases being published within a very short initial period. This is strong evidence of abandonment for a dependency that may need fixes or updates.
The repository recorded no commits and no active maintainers in the last three months, while its last push was in 2022. The lack of recent source activity materially increases maintenance risk.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a broader support community.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency and maintenance gap, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.