The source still matches the package and includes a README, license, and release notes. Its workflow uses unpinned actions and the project has no security policy, so future updates deserve extra scrutiny.
58%
Total Score
50
83
50
The registry shows no releases in the last 12 months and the latest release was about 10 years ago, which raises abandonment concerns. The recently pushed repository provides some compensating evidence, but not a normal release cadence.
One contributor made all commits in the last 3 months, leaving maintenance highly concentrated. The individual-owned project has no organizational backing shown to offset that concentration.
Only one commit was recorded in the last 3 months, indicating limited recent maintenance activity. This partially aligns with the stale registry release history and lowers confidence in ongoing support.
The repository reports no build tools and no security-scanning tools. For a small front-end library this is a hygiene weakness rather than a severe adoption blocker.
No security policy is present in the repository, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.