The package is well documented for consumers and has no install-time scripts. Its source has little public adoption and limited security process, so pinning this old release needs a replacement plan.
32%
Total Score
25
61
50
The package has had no release in about 3 years and 11 months, with all 5 releases concentrated in roughly 6 days. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and archival notice. This materially increases maintenance risk.
No license declaration or license file was detected in the package or repository. This creates a material adoption and transparency concern.
The repository is owned by an individual user rather than an organization, so the two-person registry maintainer list does not demonstrate organizational backing. This provides little evidence of ongoing support capacity.
The repository name does not match the package name, and the README package mention could not be confirmed. Although this may be a sub-package relationship, the linkage is less transparent.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.