The package includes tests, a license, documentation, and only one runtime dependency. Maintenance has been inactive for about 2 years 8 months, with no security policy and no clear package reference in the repository.
58%
Total Score
50
100
80
83
Only two releases exist, with no release in the last 12 months and a median interval of about 2 years 10 months. This indicates slow or stopped maintenance, though the latest release is stable.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the last push occurring about 2 years 8 months ago. This raises abandonment risk.
The repository name does not match the package name and its README does not mention the package, so the ownership link is not clearly demonstrated. This is a transparency concern, although the repository file tree matches the published artifact.
The repository has no security policy. That weakens vulnerability-reporting transparency, but it is a moderate gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.