It includes an MIT license, tests, a README, and release notes for the assessed version. Its single-maintainer setup and lack of security scanning leave little support beyond the published artifact.
18%
Total Score
33
67
88
Packagist marks the entire package as abandoned and names small/plural as its replacement. This is a severe adoption warning even though the assessed release itself is stable.
All three releases were published within about two days, and there have been no releases in roughly four years. The absence of recent maintenance materially increases abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus. This is not offset by the repository being technically unarchived.
Only one registry account has publish access. That is a thin publishing base for an independently backed project and increases continuity risk.
The repository is owned by an individual user rather than an organization, so the one-maintainer registry profile is not compensated by visible organizational backing.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.