It has a clear MIT license, matching source repository, readable documentation, and a recorded release note. The single maintainer, six-year release gap, and absent security policy limit confidence for a long-lived dependency.
60%
Total Score
50
86
83
The latest registry release was in December 2019, roughly 6 years and 9 months before collection, with no releases in the last 12 months. This is the main maintenance concern despite a previously regular release interval.
The registry lists one maintainer, which gives the package a thin publishing base and increases continuity risk. The linked source repository matches the package and owner, providing some accountability.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no recent development activity. The repository was pushed recently according to repository_archived, but that does not show ongoing code maintenance.
There were no new or closed issues or pull requests in the last month, while 6 issues and 10 pull requests remain open. This suggests unresolved maintenance demand, though the counts alone do not establish abandonment.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, but it is not severe enough to outweigh the package's other positive evidence by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.