The small codebase is clearly identified, licensed, and has a useful README. It has no tests or security policy, and one maintainer leaves limited visible assurance for future fixes.
58%
Total Score
50
67
75
The package has only two releases since August 2017, with no release in the observed last 12 months and a median interval of about 5.4 years. This is strong evidence of limited maintenance momentum.
The registry lists one maintainer, while the repository owner is an individual rather than an organization. Combined with inactive recent commits, this leaves limited visible maintenance capacity.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last release having been published in December 2022. This raises abandonment risk.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a modest transparency and maintenance concern for a package handling provider credentials.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.