The package includes tests, a clear README, a license, and only one runtime dependency. Its single-person ownership, absent security policy, and minimal repository activity provide little ongoing assurance.
35%
Total Score
38
100
72
75
Only two releases exist, both from May 2016, and there have been no releases in roughly 10 years. This strongly raises abandonment risk despite the package remaining available.
There were no commits and no active maintainers in the last three months, following a last repository push in 2016. This is strong evidence that the project is effectively unmaintained.
Only one registry maintainer is listed. Because this is a user-owned project rather than organization-backed, the narrow visible publishing base offers limited continuity assurance.
The repository is owned by an individual account rather than an organization. Combined with the single listed maintainer and long inactivity, this provides limited evidence of durable project backing.
There are no open issues or pull requests and no recent activity. While a clean tracker can be benign, in this case it is consistent with the long-standing absence of maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.