The package has a very short README and no repository security policy. Its stable version, minimal dependency surface, and organization-owned repository provide some supporting context, but the project remains young.
55%
Total Score
75
100
67
83
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. That creates a real adoption and redistribution concern for an open-source dependency.
A README is present, which helps consumers, but it contains only 12 characters. The absent tests and changelog are normal for a published package and are not treated as gaps.
All three releases were published within roughly 1.4 hours, and the latest release is 142 days old. This shows initial release activity but no sustained cadence afterward.
The repository recorded zero commits and zero active maintainers in the last three months. Because the project is only 142 days old, this indicates limited recent maintenance rather than long-term abandonment, but it still lowers confidence.
The repository name does not match the package name, and its README does not mention the package. Although the owner matches the registry namespace, the link between this artifact and the repository is not clearly documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.