The MIT license, included tests, and lack of install-time scripts are reassuring. However, the package has no README, no security policy, and only one registry maintainer, leaving consumer guidance and response capacity unclear.
58%
Total Score
50
70
75
The artifact includes tests, and the source repository also has tests, which supports basic maintainability. It has no README, leaving consumers without documented usage guidance for this library package.
This is the only release, published about 18 months ago, with no releases in the last 12 months. That limited history reduces confidence in ongoing maintenance but does not by itself make the package unfit.
The repository recorded no commits and had no active maintainers in the last three months, indicating a currently inactive project. The repository is not archived, which is a modest compensating signal.
The repository has zero stars and forks and one watcher, providing little community evidence or external review. Popularity is only supporting evidence, so this reinforces the maintenance concerns rather than determining the verdict.
The linked repository has no security policy, so there is no stated process for reporting or handling security issues. This is a transparency and response-capacity gap, though not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.