The package is very small, with no tests and one maintainer, while its declared MIT license conflicts with the included GPL-3.0 license file. Its last recorded repository activity was over two years ago, and the project has no security scanning.
38%
Total Score
25
64
50
The package had four releases clustered around February 2024, but none in the following 12 months and the package is now about two and a half years old. This strongly increases abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating that maintenance has effectively stopped.
The manifest declares MIT and a license file is present, but the artifact license file was detected as GPL-3.0. This unresolved mismatch creates a real adoption and compliance concern.
Only one registry maintainer is listed, leaving little visible publishing redundancy for a package that also shows no recent activity. The repository is user-owned, so there is no organizational backing to compensate for that thin base.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide no additional maturity or community support signal.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.