The MIT license and lack of install-time scripts reduce adoption friction. Use it only if you can verify ownership and support a fork, because maintenance evidence is weak.
40%
Total Score
25
57
75
This is the only release, published over five years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance or release maturity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being over five years ago. This is a substantial abandonment concern.
Only one registry maintainer is listed, which limits the visible contributor base. The user-owned project backing makes that normal publishing hygiene, but no active repository work offsets the continuity risk.
The package has no README, tests, or changelog, although the exact version has a GitHub release and the repository uses GitHub releases. The missing consumer documentation and tests are meaningful gaps for a small integration library.
The repository name does not match the package name, and no README mention was available to establish the connection. A mismatched repository makes source ownership and maintenance harder to verify.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.