The stable version and matching organization repository provide useful traceability. The package is extremely small and lacks a security policy; its maintenance history remains a long-term dependency risk.
42%
Total Score
50
69
83
Only two releases exist, and the latest was published more than five years ago, with no releases in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history and increasing abandonment risk.
Neither the package metadata nor the artifact or repository contains a recognized license. That creates a material adoption and legal-transparency concern.
Only one registry account has publish access. The organization-backed repository partly compensates for the thin registry maintainer list, but it still leaves limited visible publishing redundancy.
A GitHub release and a README are present, but the README is only 21 characters and the package has no tests or changelog. The missing tests and changelog are normal packaging practice, while the minimal documentation is a real consumer gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.