The package has a minimal README, no security policy, and no security scanning. Its single maintainer and inactive repository leave maintenance capacity and future compatibility uncertain.
43%
Total Score
33
72
83
There has been only one release, published over seven years ago, with no releases in the last 12 months. This strongly suggests the package may be abandoned, despite the absence of registry deprecation.
The repository had no commits and no active maintainers during the last three months. Combined with the long gap since its last push, this is strong evidence of abandonment risk.
Only one registry maintainer is listed, and the project backing signal identifies a personal rather than organizational repository owner. That leaves limited visible publishing redundancy.
The repository is owned by an individual account rather than an organization, and no organizational backing is shown. This does not establish a problem by itself, but it provides no visible redundancy to offset the single-maintainer profile.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community adoption or external maintenance. Popularity is only supporting evidence, so this adds moderate caution rather than deciding the result alone.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.