Unfit to use for a new dependency: the repository is archived and the last release was about six years ago. Despite a clear license, substantial documentation, tests in the repository, and a matching source project, maintenance and security support are no longer dependable.
18%
Total Score
50
100
60
75
The package has 43 releases but none in the last 12 months; its latest release was on March 21, 2020, about six years and six months before collection. This long release gap strongly indicates that current maintenance cannot be relied on.
The linked repository is explicitly archived, which is a severe abandonment risk for a package that provides application functionality and may need compatibility fixes. The recorded push date does not offset the repository's archived status.
All recent commits came from one contributor, giving the project a complete single-person commit concentration. With a user-owned project rather than organization backing, there is no shown handoff capacity to reduce this risk.
Only 2 commits were recorded in the last 3 months, with one active maintainer, providing little evidence of ongoing development or support. This is consistent with the archived repository and does not compensate for the stale release history.
The repository has no security policy, so users have no documented process for reporting or handling vulnerabilities. This is an additional transparency gap, especially concerning for an archived package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.