There is no license information, and the README is only seven characters long, limiting clarity for consumers. The small codebase is inspectable, but its lack of tests and security policy adds little assurance for a dependency this old.
44%
Total Score
0
33
50
This package has had only one release, published about eight years ago, with no releases in the last 12 months. That strongly indicates abandonment risk, although the repository is not archived.
The repository has had zero commits and zero active maintainers in the last three months, consistent with no development since the initial 2018 release. No newer release evidence compensates for this inactivity.
No registry license is declared, no license was detected, and neither the package nor repository contains a license file. Developers cannot clearly establish the terms for using or redistributing this dependency.
The package includes a README, but it is only seven characters long and provides no useful usage guidance; it also has no tests. The GitHub release for this version is a small positive, while absent tests are normal packaging practice and not independently concerning.
The repository has no security policy. For a package with no recent maintenance activity, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.