The package is small and has a simple dependency profile, while its stable version and organization-backed repository add some reassurance. Its low visibility and absent security policy leave little independent evidence for long-term support.
58%
Total Score
100
100
75
83
Neither the package nor the linked repository declares or includes a detectable license. That creates a real legal and adoption risk for dependents.
The published artifact has no README, which limits consumer guidance for this library. The absence of tests and a changelog is normal packaging practice and is not a concern by itself.
Only two releases exist, both from August 2023, with no release in roughly three years. This materially weakens evidence of active maintenance.
The repository has zero stars and forks and only four watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little independent evidence of maturity or community support.
The linked repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. This is a hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.