Documentation is minimal, and the repository has no security policy. The package is licensed and not deprecated, but its long inactivity makes adopting this release a liability.
38%
Total Score
100
58
50
The latest release was in December 2017, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having five historical releases.
The package includes a README, but it is only 14 characters long and offers virtually no guidance to consumers. Missing tests and a changelog are normal for a published artifact and are not counted against it.
The repository name does not match the package name and the README does not mention the package. Although the organization backing is consistent, this still leaves some uncertainty that the linked repository is the intended project source.
The repository is not archived, which is a positive, but it was last pushed in January 2018. That compensates for formal archival status only; it does not offset the prolonged lack of maintenance.
The repository has no security policy. For a library that parses and constructs search queries, this weakens transparency and maintenance hygiene, although it is not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.