The package has clear licensing, a focused dependency set, repository tests, and organization backing. Its tiny user base and missing security policy add little reassurance for future maintenance; pin this version if you adopt it.
48%
Total Score
50
100
75
50
The package has had no release in nearly six years, despite 13 releases between 2018 and 2020. This strongly lowers confidence that current issues or platform changes will be addressed.
The repository recorded zero commits and zero active maintainers in the last three months, with the last push in January 2021. That is strong evidence of inactive maintenance.
The package defines post-install and post-update scripts, which increase installation complexity and execution surface. No evidence here shows that the scripts are harmful, so this is a modest hygiene concern.
The repository has 2 stars, 0 forks, and 1 watcher, providing very little community evidence to compensate for the inactive maintenance record.
The repository has no security policy. This is a transparency and response-process gap, though it is less severe for a small focused library than for security-sensitive software.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.