The MIT declaration conflicts with the BSD-3-Clause license file, and the repository has no security policy. A substantial README, tests, stable version, and minimal dependencies provide useful adoption support despite the aging codebase.
44%
Total Score
100
100
69
83
The last release was in August 2016, with no releases in the past 12 months despite a package age of over 11 years. This is strong evidence of abandonment risk.
The package declares MIT and includes a license file, but the detected BSD-3-Clause text does not match the declaration. The release is licensed, yet the mismatch reduces transparency.
The repository has only 4 stars and 1 fork, indicating limited external adoption and review. Popularity is supporting evidence rather than a verdict, so this is a modest concern.
The repository is not archived, which is a compensating sign, but its last push was also in August 2016 and does not offset the long release gap.
The linked repository has no security policy. For a routing library, this weakens vulnerability-reporting transparency, though it is a secondary concern compared with the release inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.