The artifact is small and focused, includes a README, and has no install-time scripts. The conflicting Apache-2.0 declaration and MIT license file create licensing uncertainty, while the absent security policy leaves limited guidance for reporting issues.
38%
Total Score
0
38
50
The package has only two releases, both published within minutes in October 2016, and none in the last 12 months. Nearly 10 years without a release is strong evidence of abandonment risk.
The repository has no commits and no active maintainers in the last three months, consistent with the nearly 10-year-old release history rather than active maintenance.
The artifact declares Apache-2.0 but its LICENSE file is detected as MIT, although license files are present in both the artifact and repository. The mismatch warrants clarification before adoption.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these figures provide no external adoption signal to offset the maintenance concerns.
The linked repository has no security policy. For a networking and RPC library, the absence of a documented vulnerability-reporting path is a transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.