The package includes a valid license and release notes, and its repository is not archived. Its documentation is very brief, with no demonstrated security policy or repository adoption, so long-term support remains uncertain.
58%
Total Score
50
75
50
Only one registry publishing account is listed. The repository is owned by a user rather than an organization, so there is no provided backing signal to offset the narrow maintainer base.
The package is less than one day old with only two releases, so there is not yet enough history to demonstrate sustained maintenance or release stability.
The repository shows zero commits and zero active maintainers in the past three months, while the package is newly published. This limits evidence of ongoing maintenance, though the very recent age prevents treating it as abandonment by itself.
The repository name matches the package, but the package name does not appear in its README. The matching repository name reduces the concern, yet the missing README reference leaves package ownership and consumption context less explicit.
The linked repository has no security policy. For a library handling database, mail, networking, and cryptographic helpers, this is a transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.