The stable major version and small dependency surface make it easy to inspect. The MIT declaration conflicts with the Apache-2.0 license file, and workflows use two unpinned actions.
45%
Total Score
33
100
75
75
The package has had no registry release in over six years, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite its earlier regular releases.
There were no commits or active maintainers in the measured three-month period. Combined with the old latest release, this indicates sustained maintenance inactivity.
A license file is present, but it identifies Apache-2.0 while the manifest declares MIT. That mismatch reduces licensing clarity for consumers.
The registry namespace and repository owner match, but both are associated with an individual account rather than organizational backing. This offers limited demonstrated maintenance capacity.
There was no issue or pull request activity in the last month, and three issues remain open. This provides no evidence of current maintainer responsiveness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.