Risky to adopt without strong justification. The package has had no release or repository activity since April 2016, and it has no license file or declaration; its small, transparent wrapper and lack of deprecation keep it from being unfit outright.
42%
Total Score
50
67
90
Only two releases were published, both in April 2016, with no releases in the last 12 months. This long-standing absence of updates is a strong abandonment concern, although the package is intentionally a very small wrapper.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful repository activity since 2016. This is the strongest reason to view the release as risky to depend on.
Neither a declared license nor a license file was found in the package or repository. This creates a real legal and transparency concern for dependency use.
A single registry maintainer is consistent with a small personal project, but it leaves little visible publishing redundancy. The repository is owned by the same individual, so this is a limited concern rather than evidence of an ownership mismatch.
There are no open issues or pull requests and no recent issue or pull-request activity. While this may fit a tiny stable wrapper, it provides no evidence of an active maintenance community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.