It includes a README and tests, uses no install-time scripts, and has a small dependency footprint. The stable version and explicit MIT declaration provide useful context, though the artifact also contains an Apache-2.0 license file.
45%
Total Score
50
75
50
The package declares MIT and includes a license file, but the detected file text is Apache-2.0, creating an unresolved licensing mismatch for consumers.
Only two releases were published, both in May 2018, with no release in about 8 years. This is strong evidence of abandonment risk, despite the package reaching a stable major version.
There were no commits and no active maintainers in the last three months. Combined with the repository's last push in 2018, this materially increases the risk that defects will not be fixed.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, the lack of a direct mention weakens confidence that the linked repository is the authoritative source.
The linked repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less significant than the package's long-term inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.