45%
Total Score
50
71
75
The repository name does not match the package, and its README does not mention the package. That leaves the source relationship and release provenance unclear, beyond an ordinary monorepo naming mismatch.
The package has one registry publishing account. A single maintainer can maintain a small library, but there is no provided evidence of broader continuity or review capacity.
The artifact includes a README, but its 114-character excerpt is malformed and generic rather than useful consumer documentation. Missing tests and changelog files are normal for a published artifact and do not add concern.
Only two releases were published on the same day, and the latest release was about 198 days ago. This provides little evidence of sustained maintenance after the initial publication.
The linked repository has no security policy. This is a transparency gap, though it is less serious for a very small package than evidence of unsafe release automation would be.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.