The source layout is focused, with clear usage documentation, stable versioning, a permissive license, and no install-time scripts. The single-maintainer project has limited adoption and no security tooling, so pinning this release is prudent.
57%
Total Score
50
100
81
75
Only one registry account has publish access. Combined with individual repository ownership, this suggests limited publishing and maintenance redundancy, although registry access alone does not prove who actively maintains the code.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the thin maintainer base.
The package has only two releases, with the latest published about 16 months ago and no releases in the last 12 months. This is meaningful evidence of stalled maintenance for a library still at an early maturity level.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This raises abandonment and maintenance-response risk.
The repository has one star, one watcher, and no forks, providing little evidence of broad community use or external maintenance capacity. Low popularity is supporting evidence rather than a verdict on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.