Usable with caveats for a static sample-media package. It is clearly licensed, stable, and has a release note, but it has had no release or repository activity for over two years and the linked repository name does not match the package name.
68%
Total Score
50
72
75
The registry namespace and repository owner are different user identities rather than an organization-backed project, so the small maintainer context provides limited evidence of institutional support.
Only two releases were published, with none in the last 12 months; the latest release was over two years ago. That is a meaningful maintenance concern, although the package appears intended as largely static sample data.
There were no commits or active maintainers in the last three months, consistent with the long period without releases and indicating limited ongoing maintenance.
The repository name does not match the package name, and no README package mention was available. That creates some uncertainty about repository ownership or package provenance, even though the file tree is consistent with a media-only package.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these values provide no additional confidence in long-term maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.