The package has clear documentation, tests, and a matching source repository, but its registry and repository have seen no activity since June 2015. The Apache 2.0 declaration conflicts with the detected MIT license, and the project has no security policy.
42%
Total Score
33
67
83
The package has 38 releases but none in the last 12 months, and its latest release was over 11 years ago. This strongly indicates abandonment risk despite its established history.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push, this is strong evidence that maintenance has stopped.
A license file is present, so the release is licensed, but the manifest declares Apache 2.0 while the artifact license file is detected as MIT. That mismatch reduces transparency about the applicable terms.
The source repository is owned by an organization, which provides some project backing context, but the observed release and commit activity shows no current maintenance.
There were no new or closed issues or pull requests in the last month, and no pull requests were open. This is consistent with the broader evidence of an inactive project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.