The package is small, licensed, and has no install-time scripts, so its contents are easy to inspect. Its minimal README offers little integration guidance, while the repository shows no tests or security process. Pin v0.0.2 only if you accept its dormant maintenance.
42%
Total Score
50
50
83
The package has had only two releases, both in March 2017, with no release in about nine years. That is strong evidence of dormant maintenance for a dependency.
Only one registry maintainer, shurizzle, is listed. A single maintainer can be adequate for a small package, but it provides limited apparent continuity if the project needs future fixes.
The artifact includes a README, but it is only 16 characters long and provides no practical usage guidance. Missing tests and a changelog are normal for published artifacts and are not counted as gaps here.
The repository name does not match the package name, and its README does not mention the package. That raises a caution that the repository association may not clearly establish package ownership.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no external adoption or maintenance signal to offset the long inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.