The package includes a README, tests, an MIT license, and no install-time scripts. Its single-maintainer, low-adoption project has no security policy, limiting confidence in future support.
38%
Total Score
50
100
67
75
Only four releases were published, all by 2016, with no releases in roughly 10 years. That is strong evidence of abandonment risk for a dependency.
One registry maintainer is consistent with a small user-owned project, but it provides little maintenance redundancy when combined with the absence of recent releases.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures reinforce that the project has limited visible adoption.
The repository is not archived, which preserves access, but its last push was in May 2016 and does not offset the long period without activity.
No security policy was found. This is a minor transparency gap, especially for a package that processes remote RSS content, though it is less significant than the maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.