The package is small and clearly licensed, with tests and no install-time scripts. Its tiny user base, single registry maintainer, absent security policy, and no activity for over six years make future fixes and support unlikely.
42%
Total Score
33
72
83
Only two releases were published, both in 2020, and there have been no releases in over six years. This is strong evidence of an inactive project, despite the short eight-day interval between its initial releases.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push being over six years ago. This materially raises abandonment risk.
Only one account has registry publish access, leaving little visible publishing redundancy. The linked project is user-owned rather than organization-backed, so no provided evidence compensates for that thin maintainer base.
The registry namespace and repository owner match, and the owner is identified as an individual user. This supports package identity but provides no organizational backing to offset the thin maintenance base.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no evidence of a broad support community.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.