Consumer documentation is extremely thin, and the release has no license declaration or detected license. The repository also lacks security scanning and a security policy, leaving limited transparency for maintenance and responsible disclosure.
43%
Total Score
25
69
83
The latest release was published over three years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk despite three historical releases.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long release gap and indicating no current maintenance activity.
Neither the package metadata nor the artifact or repository contains a recognized license, leaving the legal terms for dependency use unclear.
Only one registry maintainer is listed. That is consistent with an individual-owned project, but it leaves little visible publishing redundancy when combined with inactive repository activity.
A README is present but contains only five characters, providing almost no integration guidance; the absence of tests and a changelog is normal packaging practice and is not a concern by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.