The package is very small and has no tests, changelog, security policy, or security scanning. Its stable release and minimal dependency set help, but five years without commits or releases leaves maintenance and compatibility risk.
42%
Total Score
0
100
61
75
The latest release was nearly five years ago, and there were no releases in the last 12 months. This is strong evidence of stalled maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving compatibility issues unlikely to be addressed.
The artifact declares MIT but its license file is detected as Apache-2.0, creating an unresolved licensing inconsistency despite a license file being present.
The artifact has no README, tests, or changelog, and the repository also reports none. The tiny five-file plugin makes the missing test and changelog less decisive, but the absent README reduces consumer transparency.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no additional evidence of an active support community.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.