The repository is minimal, and its README offers little integration guidance. MIT licensing and organization ownership provide useful provenance, but the project has no security scanning and only one registry publisher.
42%
Total Score
50
72
67
The latest release was in December 2019, with no releases in nearly seven years. This is strong evidence of abandonment risk for a library dependency.
There were no commits or active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Only one account has registry publishing access. That is a narrow publishing base, although organization backing provides some compensation.
The artifact contains only four files, including two source files, indicating a very small SDK with limited visible project material. Its minimal structure is not inherently unsafe, but it leaves little evidence of maturity.
A README is present, but it contains only 15 characters and offers little integration guidance. Missing tests and a changelog in the published artifact are normal packaging practice and are not counted against it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.