It has a small, clear artifact with tests, a README, and a matching repository. The single maintainer and minimal project footprint leave little evidence of ongoing support.
52%
Total Score
50
100
88
88
The package declares no license, contains no license file, and the repository also has no license file. This creates a real legal and adoption concern.
A single registry maintainer creates a thin publishing base and limited observable continuity. The linked repository is user-owned, so there is no organizational backing signal to offset that concern.
This package has only one release, published 18 months ago, with no releases in the last 12 months. That provides little evidence of continued maintenance.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with a project that may be dormant. Its recent release history does not provide compensating evidence of ongoing work.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though not severe enough to determine the score alone.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.