The package is small and well-scoped, with tests, a README, no runtime dependencies, and no install scripts. The linked repository has no security policy, and its minimal footprint offers little evidence of ongoing support.
42%
Total Score
38
100
67
88
Only one release was published, on May 17, 2021, and there have been no releases for about 5 years. This is strong evidence of abandonment risk for a dependency.
There were no commits or active maintainers in the last 3 months, alongside a last push in May 2021. The prolonged absence of observed maintenance materially increases abandonment risk.
There is one registry maintainer. That is a narrow publishing base, and the repository activity provides no evidence of a broader active team to compensate.
The repository is owned by an individual user rather than an organization, so the single maintainer is not supported by visible organizational backing.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with an inactive project, though it does not independently prove abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.