Usable with caveats: it is actively developed, clearly licensed, and has a matching source repository, but it is only eight days old with one contributor and no tests or security policy. Depend on it only after reviewing the small codebase and accepting its limited track record.
68%
Total Score
63
100
81
90
A README is present, but neither the artifact nor repository contains tests or a changelog. For this small package that is a real transparency and maintenance gap, despite the concise source layout.
The repository is owned by a user rather than an organization, so the single-maintainer concentration represents a genuine continuity risk rather than normal organization publishing hygiene.
The package is only 8 days old with 3 releases, so maintenance and compatibility over time are not yet demonstrated. Recent publishing activity is a positive early signal but cannot substitute for a longer track record.
All 10 recent commits came from one contributor, leaving no demonstrated backup maintainer and increasing continuity risk for this user-owned project.
One issue was opened in the last month and none were closed, but the repository is only 8 days old. This is a minor unresolved-maintenance concern rather than evidence of a neglected mature project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.