A clear MIT license, focused source layout, and an organization-backed repository improve transparency, but the missing security policy leaves less evidence for responsible maintenance. No release or commit activity has occurred for nearly four years, creating substantial abandonment risk for this dependency.
43%
Total Score
0
79
75
This is the package's only release, published nearly four years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long gap since its last release. This is a substantial abandonment concern.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible uptake provides no compensating signal for the stalled maintenance.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented. This is a maintenance-transparency gap, though it is less severe than the lack of recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.