Licensing is clear, the package includes tests, and installation has no lifecycle scripts. Its small dependency surface and matching organization repository add transparency, while the missing security policy limits operational reassurance.
38%
Total Score
50
100
79
75
Only two releases were published, both in August 2014, with no release in roughly 12 years. This strongly indicates the package is no longer maintained, despite the initially short five-day release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being in November 2014. This is strong evidence of abandonment rather than merely a slow release cadence.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a modest transparency gap, but it is secondary to the package's long inactivity.
Version 0.0.2 is not a stable major release, so the API may be immature or subject to breaking changes. The release history and repository state make this more concerning, although it is not itself evidence of a withdrawn release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.