The small artifact is clearly tied to an organization-backed project and has a stable version with proper licensing. Its documentation is extremely thin, and recent maintenance evidence is limited.
65%
Total Score
75
80
50
The artifact includes a README, but it is only 19 characters and provides little integration guidance. Missing tests and changelog files are normal packaging practice and do not add concern here.
The package has five releases over about five years, but none in the past 12 months and the latest release was about 16 months ago. This suggests slowing maintenance, though the package may be intentionally stable.
The repository recorded no commits and no active maintainers in the past three months. That is meaningful abandonment risk for a dependency, despite the repository not being archived.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.