Tests, documentation, a changelog, and an MIT license make the package easy to inspect, while organization backing and no runtime dependencies reduce adoption friction. Pinning it would leave you responsible for an experimental codebase with little evidence of ongoing support.
38%
Total Score
50
100
67
75
The package has only one release, published about 10 years and 11 months ago, with no releases in the last 12 months. That strongly suggests abandonment despite the repository remaining available.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the only release. This is strong evidence of inactive maintenance.
The linked repository is not archived, which preserves the possibility of future maintenance. However, its last push was about 10 years and 10 months ago, so this does not offset the stale release history.
The repository has no security policy, reducing transparency around vulnerability reporting. This is a secondary concern for a small, inactive package, but it adds to the adoption risk.
The latest release is v0.1.0, indicating an immature project rather than a stable major release. Its release notes also explicitly describe it as intended for testing rather than production use.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.