The package is a very small project with one registry maintainer and no tests or security policy. Its MIT licensing, clear README, matching repository, and current release provide useful transparency, but the limited history and absent recent commit activity leave maintenance risk.
62%
Total Score
50
83
75
Only one account has registry publish access. Because the repository is user-owned rather than organization-backed, this leaves a thin maintainer base and increases continuity risk.
The registry namespace and repository owner match, but the owner is an individual account. This supports package ownership alignment without providing organizational backing.
The package is 483 days old but has only 2 releases, with 1 release in the last 12 months and a median interval of about 484 days; this indicates a thin maintenance history.
There were 0 commits and 0 active maintainers in the last 3 months. Although the repository was pushed on September 20, 2026 for this release, the measured activity still gives weak evidence of ongoing maintenance.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these counts provide little evidence of broad review or community support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.