The stable API and tiny artifact keep adoption simple. A single maintainer and limited project security practices add maintenance and transparency concerns.
45%
Total Score
25
40
The package has only two releases, with the latest in April 2018 and no releases in the last 12 months. That long period without updates raises abandonment risk, even for a small stable utility.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push, this supports a substantial maintenance concern.
The manifest declares GPL-3.0-or-later, while the repository license file is recognised as MIT; this mismatch creates uncertainty about the terms covering the release.
Only one registry account has publish access, leaving little publishing redundancy. The repository is user-owned rather than organization-backed, so no compensating project backing is shown.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish that this repository belongs to the published package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.