The repository is extremely small, with one maintainer and no security policy. Its license and minimal dependency profile reduce adoption friction, but the project lacks evidence of ongoing care.
38%
Total Score
50
100
72
75
The package has had only two releases, both in July 2017, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency released nearly nine years ago.
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. Missing tests and changelogs are not expected in every published artifact, but the absent README modestly reduces consumer transparency for a small library.
The package and repository are owned by the same individual account rather than an organization. This is not inherently unhealthy, but it provides no organizational backing to offset the thin maintenance evidence.
There have been no new or closed issues or pull requests in the past month, and the repository has no open work. Combined with the old last push, this supports a low-activity assessment.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of community support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.