The repository is correctly linked, licensed, and backed by an organization, with a changelog and no install scripts. Its tiny scope and lack of recent commits or releases leave maintenance uncertain; the missing security policy is a minor transparency gap.
58%
Total Score
67
86
83
The package has seven releases, but none in the last 12 months and the latest registry release was over seven years ago. This materially increases the risk that the published dependency is stale.
The repository recorded zero commits and zero active maintainers in the last three months. Although it is not archived, this provides weak evidence of current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with one issue and one pull request still open. This suggests limited recent project activity.
The repository has no security policy. For a small library this is a minor transparency and vulnerability-reporting gap, not evidence that the package is unsafe.
Version 0.5.0 is not marked as a prerelease, but it remains below a stable major version. That is a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.