The package has a usable README and repository tests, but only one registry maintainer and no security policy. Its license declaration conflicts with the license file, leaving an avoidable transparency concern.
38%
Total Score
50
79
83
Only two releases were published, both in October 2021, with no release in nearly five years. This strongly raises abandonment risk for a dependency.
The manifest declares ISC, while the bundled license file is detected as MIT. A license exists, but the mismatch creates a transparency and reuse concern.
One registry account publishes the package. A single maintainer is a limited resilience factor, and the concern is amplified by the lack of recent repository commits.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance despite the repository not being archived.
There were six open pull requests, three new in the last month, and none merged in that period. This suggests contribution activity is not translating into maintained changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.