The repository has 30 commits in the past three months, and the package includes a README, release notes, and no install-time scripts. Its single-contributor base, license mismatch, repository naming gap, and unpinned workflow actions warrant caution.
62%
Total Score
70
100
69
75
The artifact declares MIT but its license file is recognized as CC-BY-4.0, while a repository license file is also present. This mismatch creates genuine uncertainty about the release's licensing terms.
One registry maintainer is consistent with a small publisher, but it provides limited publishing redundancy when combined with the repository's single active contributor.
The repository owner is a user account rather than an organization, so the one-person contributor concentration is not visibly backed by an organizational maintenance structure.
This is a young package, 55 days old, with one release and no established release interval. That limits evidence of long-term stability but is not abandonment evidence by itself.
All 30 recent commits came from one contributor, leaving maintenance highly dependent on a single person. The repository owner is an individual rather than an organization, so there is no shown organizational handoff buffer.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.