The organization-owned repository is active and not archived, while the small dependency surface keeps integration straightforward. The limited release history, single recent contributor, proprietary license, and missing security policy leave important adoption risks.
58%
Total Score
67
100
63
75
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That creates a material legal and transparency concern for an open-source dependency.
This is the only release in 158 days, so there is little release history to establish maturity or long-term maintenance patterns. The project is still relatively new rather than demonstrably abandoned.
One contributor made all commits in the last 3 months, concentrating maintenance responsibility. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.
The repository recorded one commit in the last 3 months, showing some recent activity but very limited evidence of sustained maintenance.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe than abandonment or deprecation evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.