The artifact is clearly identified, with an MIT license, a usable README, and no install-time scripts. Its lone maintainer, absent security policy, and minimal repository adoption leave little evidence of ongoing support.
62%
Total Score
50
100
83
75
The repository is owned by an individual user rather than an organization, and the package has one registry maintainer. With no separate evidence of a broader team, maintenance capacity appears limited.
This package has only one release, published 644 days ago, with no releases in the last 12 months. The repository is still available, but the lack of follow-up materially weakens evidence of active maintenance.
The linked repository has 1 star, 0 forks, and 1 watcher, showing minimal independent adoption. Low popularity is supporting evidence rather than proof of poor quality, but it provides little external validation.
The repository has no security policy, leaving no documented channel or process for handling vulnerabilities. This is a modest transparency gap for a library that processes user-facing captcha input.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.