It includes a README, tests, and a clear MIT declaration, and the repository matches the package. The stable release and lack of install scripts reduce adoption risk, but there is no security policy or scanning.
61%
Total Score
50
83
83
Only one account has registry publish access, leaving little publishing redundancy. The linked repository is user-owned, so there is no organization backing to compensate for that thin maintainer base.
The registry namespace and repository owner match, but both identify an individual rather than an organization. The matching ownership supports provenance while leaving limited visible backing capacity.
The package is mature, with releases beginning about 9 years ago, but it has had no release in the last 12 months and releases are widely spaced. This points to slowing maintenance rather than abandonment by itself.
There were no commits and no active maintainers in the last three months. Combined with the absence of releases in the last 12 months, this is a meaningful maintenance concern.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of a broad support community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.