Risky to adopt: the package has had no release or repository activity for over seven years. It is not deprecated or archived and is clearly backed by a matching organization repository, but the missing license and consumer documentation add adoption risk.
45%
Total Score
100
42
Only two releases exist, with the latest published over seven years ago and none in the past 12 months. That long period without releases is strong evidence of abandonment risk, despite the stable v2.0 version.
The repository is not formally archived, which is a positive sign, but its last push was over seven years ago. The lack of recent source activity substantially outweighs the repository's non-archived status.
No license declaration or license file was found in the package or repository. This creates a material legal and adoption concern for an open-source dependency.
The package has no README, while this is a library that consumers must integrate against, so the missing usage documentation is a real transparency and usability gap. Missing tests and a changelog in the published artifact are normal packaging practice and do not add concern here.
The repository has no stars or forks and only one watcher, offering little supporting evidence of community review or ongoing use. Popularity is not decisive by itself, but it reinforces the maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.