The package is small and focused, with one runtime dependency, tests, an MIT license, and release notes. Its lone maintainer and absent security policy add modest continuity and transparency concerns.
58%
Total Score
50
100
88
75
One registry maintainer is a small continuity base for a user-owned project. It is not severe on its own, but it increases dependence on a single person.
This is the only release, published about two years ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain, though the repository is not archived.
The repository had no commits and no active maintainers in the past three months, consistent with a project that has seen no activity since its initial release. This raises abandonment risk.
The repository has zero stars and forks and one watcher, providing little supporting evidence of external review or adoption. Popularity is only supporting evidence, so this is a modest concern.
The repository has no security policy, reducing transparency about vulnerability reporting and response. The package's small scope limits the practical impact of this gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.