The package is small and has clear installation documentation. Its minimal dependencies and lack of install scripts reduce operational friction, but confirm that proprietary terms fit your project.
52%
Total Score
50
100
75
83
The manifest declares a proprietary license, with no license file detected in the package or repository. This creates a material adoption and redistribution constraint for an open-source dependency.
The repository is owned by an individual account, and no organization backing is shown. This provides little evidence of a maintenance handoff if the sole contributor becomes unavailable.
The package is young at 111 days and has four releases, with releases clustered closely together. This provides limited evidence of long-term maintenance.
All observed recent commits came from one contributor, leaving maintenance highly concentrated. The repository owner is a user account rather than an organization, so there is no provided backing evidence to offset that concentration.
Only one commit from one active maintainer was observed over the last three months. That is weak evidence of ongoing maintenance for a package intended to cover a broad API surface.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.