The MIT license, focused dependencies, README, and repository tests make it straightforward to inspect and integrate. The source is clearly tied to the package, but there is no security policy or automated workflow evidence.
38%
Total Score
0
100
79
50
The package has had no releases in over 8 years; its 25 releases are all concentrated around February–March 2018. That prolonged release silence is strong evidence of abandonment risk.
There have been zero commits and zero active maintainers in the last 3 months, consistent with the repository having stopped changing in March 2018. This materially increases abandonment risk.
The repository has only 1 star and no forks, offering little evidence of broad community adoption or a backup contributor base. Popularity is supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and response-readiness gap, though it is less severe than the long inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.