The package is licensed, tested, documented, and has no install-time scripts. Its last registry release was nearly five years ago, repository commits have stopped, and the linked repository does not identify this package in its README.
43%
Total Score
0
75
67
The latest registry release was in December 2021, with no releases in the last 12 months and a package age of nearly five years. This is strong evidence of an outdated dependency and raises abandonment risk.
There were no commits and no active maintainers in the last three months. Combined with the stale registry release history, this materially increases maintenance and abandonment risk.
The repository name does not match the package name and its README does not mention the package, so the repository may not clearly belong to this release. That weakens provenance and transparency.
The repository has no security policy. For a small package this is a transparency gap, though it is less serious than the observed maintenance concerns.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That is a modest build-reproducibility weakness, not a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.