The five-file project has no tests, security policy, or security scanning, limiting confidence in ongoing maintenance. Its Apache-2.0 license, clear repository match, and organization backing are helpful, but not enough to offset the long inactivity.
42%
Total Score
50
69
50
The latest release was about 8 years ago, with no releases in the last 12 months. That long pause is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last 3 months, consistent with the release history showing that development stopped about 8 years ago.
The artifact and repository match a very small five-file implementation, with source, manifest, README, and license present. This is transparent and simple, though it also leaves little evidence of engineering depth.
The package includes a README and publishes GitHub releases, but the repository has no tests or changelog. The README is useful but very brief, while the missing tests reduce confidence in maintenance quality.
The repository has only 2 stars and no forks, offering little community evidence or outside adoption to offset the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.