The small, tested codebase and minimal dependency surface reduce adoption friction. There is little evidence that defects or compatibility changes would receive attention, making long-term use a liability.
42%
Total Score
50
100
67
50
The latest release was in August 2017, about 9 years ago, and there were no releases in the last 12 months. This strongly raises abandonment and compatibility risk despite the package having four historical releases.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in November 2019, about 7 years ago. That provides little evidence of ongoing maintenance.
The repository has no security policy. For a small package this is a transparency gap, though the package's tests, readable source, and limited dependency surface partly reduce the concern.
Version 0.0.4 is not a stable-major release, so its compatibility expectations are weaker than those of a mature 1.x package. The absence of prerelease versions is a small compensating signal, but does not offset the long inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.