The package includes a README, repository tests, and a recent release, with no deprecation or install scripts. Pin 0.1.2 and reassess if the project’s small maintenance base stops producing updates.
58%
Total Score
67
100
80
75
The package has only 2 releases over nearly 4 years, with a median interval of about 3 years and 11 months. One release in the last 12 months shows some ongoing activity, but the long gaps lower maintenance confidence.
All recent commits came from one contributor, so maintenance is concentrated. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository had 1 commit in the last 3 months from 1 active maintainer. This demonstrates recent activity but provides only limited evidence of sustained maintenance capacity.
The repository name does not match the package name and its README does not mention the package, so the link between the registry package and source repository is less transparent. The mismatch is not explained by a stated package reference.
The repository has no security policy. For a small email-validation library this is a transparency gap, though it is less serious than missing maintenance evidence or an archived project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.