The small project is easy to inspect and has a clear README and build setup. However, it has had no releases or commits for about three years and seven months, and the license terms need clarification before adoption.
52%
Total Score
75
100
83
50
The manifest declares the package proprietary while an MIT license file is present in both the artifact and repository. The conflicting signals create legal uncertainty despite the clearly identified MIT text.
The five releases were published within a short period ending in February 2023, with no releases in the last 12 months. This indicates a long-standing maintenance gap, though a small skeleton project may require few updates.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with no observable development since February 2023. That materially increases abandonment risk.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a modest transparency gap for a project intended to seed applications.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.