Clear documentation, tests, and licensing make the package understandable to adopt. Its very small user base and missing security process add uncertainty for a long-lived dependency.
55%
Total Score
75
100
71
75
The package has made three releases, but its latest release was about two and a half years ago and there were no releases in the last 12 months. This materially raises abandonment risk.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this indicates currently inactive maintenance rather than merely a quiet release schedule.
The repository has one star, one fork, and no watchers. Popularity is only supporting evidence, but these figures provide little external evidence of sustained adoption or community support.
The linked repository is not archived, so the project remains administratively available. Its last push was about two and a half years ago, which aligns with the maintenance concern from the release history.
The repository has no security policy and no security-scanning tools. For a package that distributes bindings and relies on a native library, this leaves vulnerability reporting and security checks less transparent.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.