The package has a clear README, tests, no runtime dependencies, and a detected GPL-2.0 license. Its small footprint and lack of registry deprecation reduce some adoption concerns, but ongoing maintenance and repository identity remain uncertain.
43%
Total Score
100
67
75
This is the only release, published over 11 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.
The linked repository name does not match the package name and its README does not mention the package. This weakens confidence that the repository is the intended source for this release.
The repository is not archived, which preserves a path for maintenance, but it was last pushed on the same day as the sole release in 2015. The absence of later repository activity is a substantial maintenance concern.
The repository has no security policy. For a small, inactive package this adds a transparency gap, although it is less consequential than the long maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.