The package includes a README, tests, release notes, and a stable non-deprecated release. Its single-maintainer project has had no release in about six years, no recent commits, no security policy, and no license evidence, making it a risky long-term dependency.
43%
Total Score
33
72
75
The latest release was published about six years ago, with no releases in the last 12 months. Only three releases exist, indicating substantial abandonment risk despite the earlier release cadence.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
Neither the package metadata nor the package or repository contains license evidence. This creates a real transparency and adoption concern for a dependency.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is little visible redundancy in publishing or maintenance capacity.
The repository is owned by an individual account, not an organization. This does not prove a problem by itself, but it provides no organizational backing to compensate for the thin maintainer base.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.