The README is only 260 characters, and the project has no license or security policy for consumers to inspect. The source repository is not archived, but there have been no commits in the last three months and no registry releases since August 2018.
42%
Total Score
0
50
50
The package has had no release in more than eight years, with zero releases in the last 12 months. This is strong evidence of abandonment for a library that integrates with an external courier API.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap rather than showing active maintenance between releases.
Neither the package nor the linked repository provides a declared or detected license. That creates a real adoption and redistribution concern for an open-source dependency.
A README is present, but it is only 260 characters and gives very limited integration guidance. The absence of tests and a changelog in the package is not treated as a gap because those commonly belong in the source repository.
The repository name matches the package, but its README does not mention the package. That weakens the evidence that the repository documents and actively supports this published dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.