The package has a minimal footprint, one runtime dependency, and no install-time scripts, limiting integration risk. The explicit BSD-3-Clause license is a positive, but the small project provides little documentation or security process.
32%
Total Score
25
56
83
All four releases were published on 2 April 2019, within minutes of one another, and there have been no releases in roughly seven years. This strongly suggests the package is no longer maintained.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive since April 2019. This is strong abandonment evidence.
The linked repository name does not match the package name, and no README mention was found. That raises uncertainty about whether the repository is the package's actual source.
The artifact has no README, tests, or changelog, although missing tests and changelogs are normal for published artifacts. The missing README is a minor consumer-documentation gap for a package described as an example project.
The package and repository are owned by the same individual account, which supports ownership continuity but does not provide organizational backing or compensate for the lack of activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.