ksnk/text v1.0.25 appears usable and reasonably transparent: it is a mature MIT-licensed package with a matching repository, documented usage, tests, a small dependency surface, and a current stable release. The main concerns are limited observable maintenance capacity—only one commit from one contributor in the last 3 months—and very low repository adoption, alongside absent security-policy and security-scanning evidence. These concerns warrant caution for long-lived or security-sensitive dependencies, but the package is not deprecated or archived and has no major abandonment indicator.
72%
Total Score
60
100
89
90
Only one registry account has publish access. This is not itself evidence of poor maintenance, but it leaves publishing continuity dependent on a single person.
The repository is owned by a user rather than an organization, so there is no organizational backing shown to mitigate the single-maintainer continuity risk.
All recent commits come from one contributor, giving the repository a bus factor of one and creating a meaningful continuity risk if that maintainer becomes unavailable.
Only one commit was made in the last 3 months by one active maintainer. The recent commit is positive evidence of activity, but the low volume indicates limited observable maintenance capacity.
The repository has zero stars and forks and only one watcher, so there is little external adoption or community visibility to compensate if maintenance stops.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.