The package includes a README, version documentation, and a focused configuration tree. Its MIT declaration and lack of install scripts reduce adoption friction, but the narrow repository documentation and absent security policy leave limited assurance for future changes.
58%
Total Score
50
80
83
The latest registry release was over 4 years ago, with no releases in the last 12 months. Earlier releases were reasonably regular, but the long current gap lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months. Although the package is small and may change infrequently, this provides no evidence of current maintenance capacity.
The repository name matches the package, which supports the linkage, but the README does not mention the package name. That weakens transparency about whether the repository is the intended source.
The linked repository has no security policy. This is a modest transparency gap for handling vulnerability reports, though the package has no observed security workflow or install-time scripts.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.