Its MIT license, tests, minimal runtime dependency, and matching source repository improve transparency. The lack of security tooling and a single publish maintainer leave little evidence of ongoing support.
42%
Total Score
33
100
75
83
Only two releases exist, with none in the last four years; this is strong evidence that maintenance has stopped, although the package is not marked deprecated.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and indicating a high abandonment risk.
One registry publishing account is recorded. Because the repository owner is an individual user rather than an organization, this provides limited evidence of maintainer redundancy.
The repository is owned by an individual user rather than an organization, so there is no observed organizational backing to compensate for the thin maintainer base.
Zero stars and forks and one watcher indicate little visible community adoption or external support; popularity is supporting evidence, but this increases uncertainty for a small inactive project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.