The package has frequent recent releases and is not archived or deprecated. Maintenance rests on one contributor, with no tests, security policy, or repository README confirmation, so future support is uncertain.
68%
Total Score
50
81
75
Only one registry account has publish access. The repository is user-owned rather than organization-owned, so there is no provided project-backing evidence to offset that concentration.
The artifact includes a README entry, but it has zero recorded content and the repository has no tests or changelog. Tests and changelogs are not expected in the published artifact, while the empty consumer documentation is a minor transparency gap.
One contributor made 100% of the commits in the last three months, leaving no demonstrated backup maintainer for continuity.
Only one commit was recorded in the last three months, all from one active maintainer; this is current activity but a thin maintenance signal.
The repository name does not match the package name, and README mention status is unavailable. A name mismatch can be normal for a sub-package, so this is only a limited identity-transparency concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.