The repository matches the package and includes a usable README, while its simple dependency set limits installation surprises. Its lone maintainer and absent security policy leave little evidence of ongoing support.
38%
Total Score
50
100
67
50
The package has only one release, published in March 2017, with no releases in the last 12 months. This long period without updates is strong evidence of abandonment risk.
The artifact contains a license file and the repository also has one, but the manifest declares MIT while the detected license is Apache-2.0. That mismatch creates avoidable licensing uncertainty.
Only one registry maintainer account is listed. With no organization backing shown and no recent releases, this indicates limited publishing continuity and a weak bus factor.
The repository has one star and one fork, providing little supporting evidence of adoption or a broader community that could help sustain it.
The repository has no security policy. For an SDK that handles cloud-service credentials and API calls, this is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.