This is a usable, stable-major package with a long history, a recent release, an unarchived organization-owned repository, repository tests, build tooling, dependency scanning, and restrictive workflow permissions. However, maintenance activity is thin: only five releases over roughly 5.9 years, zero commits and zero active maintainers in the last three months, no packaged README or changelog, no security policy, and negligible repository adoption. The repository-backed tests and recent release materially reduce abandonment concerns, but the package remains a moderate-risk dependency rather than a strongly mature one.
66%
Total Score
63
89
90
Only one registry account, Gregor, has publish access, creating a concentration risk. The linked repository is organization-owned, which provides some backing, but the observed registry publishing base is still narrow.
The package is about 5.9 years old and has a release within the last day, with two releases in the last 12 months. However, only five releases overall and a median interval of about 445 days indicate a sparse release cadence.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance-capacity concern. The recent release and repository push provide some counterevidence, so this is caution rather than danger.
Issue activity is quiet, with no new issues in a month and no open issues, while one pull request was opened and one issue was closed; one pull request remains unmerged. This is limited but not a severe maintenance warning.
The repository has zero stars and forks and only two watchers, showing negligible external adoption. Popularity is supporting evidence rather than a verdict, so this lowers confidence in maturity without independently making the package unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.