It has one registry maintainer, no security policy, and no observed security scanning or recent issue activity. A license file, stable version, and release notes provide basic transparency.
42%
Total Score
50
75
50
Only one account has registry publishing access. The linked project is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer becomes unavailable.
The package has had only one release, on March 30, 2021, with no releases in nearly five and a half years. This is strong abandonment evidence, despite the stable version format.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of ongoing maintenance.
The linked repository name does not match the package and its README does not mention the package, so ownership of the source is not clearly established.
The repository has no security policy. For a small package this is not severe on its own, but it reduces transparency and leaves no documented vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.