The package is small and easy to inspect, with tests, release notes, a matching repository, and a GPL-3.0 license. Its lack of security tooling adds little confidence for a dependency that has not evolved.
38%
Total Score
0
100
67
75
Only one release exists, published 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment rather than an actively maintained dependency.
There were no commits and no active maintainers in the last three months, consistent with the repository's last activity being in 2015.
The repository is not archived, which is a modest compensating signal, but it was last pushed in 2015 and does not offset the absence of current maintenance.
The repository has no security policy and no security scanning tools. These are not proof of danger, but they reduce transparency and provide little evidence of an ongoing security process.
The assessed version is a prerelease beta, and every recent release is a prerelease. That leaves API stability and long-term support uncertain.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.