The package is licensed and its repository matches the package, but it offers little evidence of ongoing care. The artifact also includes a private key, making this release a poor default dependency without careful review.
42%
Total Score
25
90
50
The artifact includes cert/pri.key alongside the package code. Shipping a private key is a serious packaging and security-hygiene concern, even though it does not by itself establish malicious behavior.
The repository recorded zero commits and zero active maintainers in the last three months, despite the release being about nine months old. This is strong evidence of limited ongoing maintenance.
Only one registry maintainer is listed, leaving little visible publishing redundancy. This is more concerning alongside the absent recent commit activity, though it does not prove abandonment.
All three releases were published within minutes on the same day, with no later releases over about nine months. That suggests a new or quickly abandoned project rather than an established maintenance cadence.
The linked repository has no security policy. For a utility package handling encryption, certificates, JWTs, and authentication, that leaves security-reporting practices and project response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.