The package is small and well documented, with tests, a matching MIT license, and a repository that is not archived. Its single release dates from March 2019, with no recent commits or releases, while install-time scripts and unpinned workflow actions add modest maintenance and supply-chain concerns.
48%
Total Score
38
100
81
67
Only one release exists, published in March 2019, with no releases in the last 12 months; this is strong evidence of an unmaintained dependency.
There were zero commits and zero active maintainers in the last three months, reinforcing the long-standing absence of active development.
Post-install and post-update scripts run during dependency operations, increasing installation complexity and supply-chain exposure compared with a package without lifecycle hooks.
One registry maintainer is consistent with a small user-owned project, but it leaves limited visible publishing capacity if that person becomes unavailable.
The repository is owned by an individual user rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.