The package is clearly licensed, documented, and has no install-time scripts. Its source has been inactive since 2017, with only two releases, no tests or security policy, and no README reference to the package name; verify ownership before adopting.
38%
Total Score
50
100
61
75
The package has only two releases, both from October 2017, and no releases in the last 12 months. Nearly nine years without a new release is strong abandonment evidence.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release and indicating no current maintenance capacity.
A README is present and describes the package, but the artifact and repository contain no tests or changelog. Missing tests reduce confidence in a small library, while the absent changelog is not a packaging defect.
The repository name does not exactly match the package name and its README does not mention the package. Although naming differences can occur in subpackages, the missing README reference makes package ownership less transparent.
The repository has only 4 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these low figures provide little external evidence of maturity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.