Usable with caveats: the release is licensed, test-backed, non-deprecated, and linked to an active, unarchived repository. However, the repository shows no commits in three months, has no security tooling or policy, and does not clearly identify this package, so maintenance and provenance deserve review before adoption.
62%
Total Score
67
100
72
90
The package has existed for about 9 years with 13 releases, but only one release occurred in the last 12 months, indicating a slow maintenance cadence despite the recent release.
There were zero commits and zero active maintainers in the last three months. The recent release provides some compensating evidence, but the lack of ongoing repository activity remains a maintenance concern.
There is one open issue and no issues or pull requests were created or closed in the last month, offering little evidence of active community maintenance.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly established. The matching owner offers limited context but does not resolve this provenance gap.
The repository has zero stars and forks and one watcher. Popularity is not required for health, but these figures provide little supporting evidence of community review or shared maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.