Risky to adopt: this package has had only one release, about 15 months ago, and no source repository is declared. The artifact contains substantial code and has a permissive license with no install scripts, but maintenance and transparency are too limited for dependable use.
42%
Total Score
50
100
50
100
There has been only one release, with no releases in the last 12 months, and the latest release is about 15 months old. This provides little evidence of ongoing maintenance.
The release history shows a single publication on 2025-06-13 and no subsequent version activity, which materially raises abandonment risk for a package intended for application integration.
One registry account has publish access, which limits visible publishing redundancy and increases single-person continuity risk. This is administrative evidence only, so it is a caution rather than proof of inactive maintenance.
The published artifact has no README, leaving consumers without package-specific usage guidance. Missing tests and a changelog are not concerns here because those normally belong in the source repository or release metadata, which were not collected.
The package remains at v0.1 rather than a stable major version, which indicates an early-stage API and increases adoption risk. It is not marked as a prerelease, so this is a caution rather than a severe release-status problem.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.