The package is small, licensed, and its repository clearly matches the published package. Its long-standing lack of maintenance and absent project tests make future compatibility harder to trust.
43%
Total Score
0
100
67
50
The latest release was over 7 years ago, with no releases in the last 12 months. Although the package has 28 releases and version 2.2.6 is stable, the prolonged silence lowers confidence in ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring over 7 years ago. This is strong evidence of abandonment risk even though the repository is not archived.
The artifact includes a substantial README, which supports consumer use, but both the published package and repository report no tests. Missing tests are not a packaging defect, yet their absence reduces confidence in future changes for a library that performs network validation.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these very low adoption signals provide no compensating evidence for the long maintenance gap.
The repository has no security policy. This is a transparency gap, though it is less significant than the maintenance evidence and does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.