The artifact includes tests, a useful README, and a release note, but its Apache-2.0 declaration conflicts with the MIT license file. The small project also has no security policy and uses two unpinned workflow actions.
62%
Total Score
50
100
78
75
The manifest declares Apache-2.0, while the included LICENSE.md and repository license are MIT. A license mismatch creates real uncertainty for downstream legal review.
The package and repository are owned by the same individual user account, so the project has a narrow backing base rather than organizational support.
The package has seven releases over roughly 6 years and no registry release in the last 2 years, indicating a slow or paused release cadence.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the old latest registry release, this raises maintenance risk.
There are no new issues or merged pull requests in the last month, with one open pull request. This offers little evidence of active community maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.