This small package has limited transparency and no visible safety process. Its source repository is inactive, has no recent contributors, and does not clearly identify the package, making long-term maintenance and provenance difficult to trust.
20%
Total Score
25
50
75
The latest release was published in April 2013, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a package developers would depend on.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no observable ongoing maintenance.
Only one registry maintainer is listed, leaving a thin publishing base. The individual-owned repository provides no organizational backing to compensate for that concentration.
The repository name does not match the package name and its README does not mention the package, leaving the package-to-source relationship unclear. This is a provenance and transparency concern.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these values provide no supporting evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.