Testing and packaging are straightforward, with a README, MIT license, and focused dependency footprint. Its small, single-owner project has no recent commits or releases, so future fixes may be slow.
58%
Total Score
50
100
93
75
One registry maintainer is consistent with an independently owned project, but it leaves little visible publishing redundancy when combined with the inactive repository.
The repository is owned by an individual rather than an organization, so the single-owner maintenance concern is not offset by organizational backing.
Only two releases exist since March 2020, with the latest on June 5, 2022 and no releases in the last 12 months; this indicates a long-standing maintenance gap.
There were no commits and no active maintainers in the last three months, reinforcing the risk that fixes or compatibility updates may not arrive promptly.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a moderate transparency gap for a library that handles environment files.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.