The package has clear documentation, release notes, and a matching source repository with an MIT license. Its maintenance record is too stale for a dependable new dependency, especially for a pre-1.0 release.
43%
Total Score
0
70
50
The latest registry release was about seven years ago, with zero releases in the last 12 months. That strongly suggests the package is no longer actively maintained.
The repository had zero commits and zero active maintainers in the last three months, consistent with a project whose last recorded push was about five years ago. This is substantial abandonment risk.
The repository has no security policy and no security-scanning tools were reported. This weakens the project's vulnerability-reporting and maintenance transparency, although it is not evidence of malicious behavior.
The package remains below 1.0, and the registry reports latest_version v0.0.5 while this assessment targets v0.0.6. The long-lived pre-1.0 status adds compatibility and maintenance uncertainty.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.