It includes tests, a changelog, a license, and active repository tooling. One recent commit came from a single contributor, while unpinned workflow actions and no security policy leave maintenance and build hygiene concerns.
65%
Total Score
50
100
93
67
The repository is owned by an individual account, so there is no organizational backing to compensate for the single-contributor maintenance concentration.
The package has had no registry release for nearly 3 years, despite 19 releases overall; this is a meaningful maintenance concern, though the repository was pushed recently.
All recent commit activity came from one contributor, and the repository owner is an individual rather than an organization, leaving a thin maintenance base.
There was only 1 commit in the last 3 months, so current maintenance activity is limited even though it has not stopped.
No security policy is present. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.