The license is present, and the repository matches the package. Its tiny, inactive project offers little evidence of ongoing support for future fixes.
42%
Total Score
50
71
75
This package has only one release, published more than five years ago, with no releases in the last 12 months. That leaves little evidence of continued maintenance.
A GPL-3.0 license file is present, so the release is licensed, but the manifest declares it as proprietary. That mismatch requires licensing review before adoption.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years.
The linked repository has no security policy. For a small, inactive library this weakens transparency and gives users no stated process for reporting vulnerabilities.
The latest version remains 0.0.1, so the package has not demonstrated a mature stable release line. Its single-release history reinforces that uncertainty.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.