Its compact structure and clear package contents make the project relatively easy to inspect. Long-term inactivity, minimal adoption, and missing security processes leave substantial abandonment and maintenance risk.
35%
Total Score
25
100
72
50
The package has had only 3 releases, all concentrated in July 2016, with no releases in the last 12 months and no meaningful subsequent release activity. This is strong evidence of abandonment risk.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository's last push in 2016. The lack of recent source activity materially increases maintenance and abandonment risk.
The package declares a post-update-cmd lifecycle script. This adds install/update execution surface that should be understood before adoption, although the signal does not show malicious or otherwise dangerous behavior.
The package and repository are owned by the same individual account, so there is no mismatch in ownership context. Individual ownership is not inherently unhealthy, but it provides less organizational continuity than demonstrated project backing.
The repository has 1 star, 1 fork, and 1 watcher, indicating very limited visible adoption. Popularity is supporting evidence rather than decisive, but this provides little external confidence or community support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.