The package has a clear MIT license, minimal runtime dependencies, and matching organization-backed source. Its only release was over eight years ago, with no recent commits, tests, or security policy, leaving maintenance and assurance weak.
38%
Total Score
50
100
67
50
This package has only one release, published over eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release inactivity. No provided signal shows ongoing maintenance.
The artifact includes a very short README and neither the artifact nor repository has tests or a changelog. Missing tests and changelog are normal for published artifacts, but the minimal README and absent repository tests reduce consumer and maintenance assurance.
The linked repository is not marked archived, so it remains technically available. Its last push was over eight years ago, making the non-archived status only limited reassurance.
The linked repository has no security policy, leaving no documented reporting or response process. This adds a transparency gap alongside the package's otherwise limited maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.