The package has a README, a minimal dependency footprint, and no install-time scripts. Its source project has no tests or security policy, while the artifact's MIT license conflicts with its proprietary declaration.
40%
Total Score
100
64
75
The package has had only two releases, both in December 2018, with no releases in the last 12 months and no newer release activity over roughly seven years. This is strong evidence of abandonment risk.
The artifact contains an MIT license file, which is positive, but the manifest declares the package proprietary; the mismatch creates legal uncertainty for consumers.
The linked repository name does not match the package name and its README does not mention the package, so the repository may not actually be the package's source.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but combined with the long lack of release activity it provides no sign of an active user or contributor community.
The source repository has no security policy, leaving no documented process for reporting or handling vulnerabilities; this is a modest transparency gap for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.