The tiny package has tests, release notes, no install-time scripts, and no runtime dependencies. Pin v1.0.2 and verify its source before relying on it in production.
34%
Total Score
100
58
100
The latest release was in July 2016, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency.
The linked repository name does not match the package name, and no README mention was found, so the repository may not actually belong to this package. That weakens source transparency.
The repository has one star, zero forks, and one watcher. Popularity is not required for a healthy package, but these figures provide little supporting evidence of active maintenance.
The repository is not archived, but it was last pushed in July 2016, which provides no meaningful compensation for the package's long release inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.