The artifact has a license mismatch, unpinned workflow actions, and no security policy. Tests, documentation, and a release note provide useful project context, but the package has little evidence of ongoing support.
55%
Total Score
50
100
81
67
The manifest declares GPL-3.0-or-later while the artifact license file is detected as MIT. The package is licensed, but the conflicting terms create adoption and compliance uncertainty.
This is the only release, published over 2 years ago, with no releases in the last 12 months. That suggests the project may be inactive, although a small stable package can remain serviceable.
The repository had no commits and no active maintainers in the last 3 months, consistent with the package's long release gap. This weakens confidence that issues or compatibility changes will be addressed.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide little external evidence of adoption or review.
The repository has no security policy. This is a transparency and incident-response gap, though it is less significant for a small package without evidence of active security-sensitive development.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.