The four-file codebase is easy to inspect, but its project practices offer little supporting evidence for long-term use. The linked repository is genuine and not archived, which reduces uncertainty about provenance.
48%
Total Score
50
50
No license is declared, detected, or included in the package or linked repository. Developers do not have clear permission to use or redistribute this dependency.
This is the package's only release, published about three years ago, with no releases in the last 12 months. That leaves maintenance and abandonment risk unresolved.
The repository has zero stars and forks and only one watcher. Popularity is not decisive for a small package, but it provides no additional evidence of community adoption or support.
The repository has no security policy. For this small package that is a transparency gap, although the absence does not by itself show a security problem.
Version 0.1.0 is not a stable major release, which is consistent with an early-stage package and adds some maturity risk alongside its lack of release activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.