A license, README, and tests make the small package easier to inspect. Its single maintainer and absent security policy leave limited support and disclosure coverage.
38%
Total Score
25
63
75
The latest release was over seven years ago, with only two releases ever and none in the last 12 months. This is strong evidence of abandonment despite the historically regular 19-day interval.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release silence. No provided signal shows recent maintenance to compensate.
Only one registry maintainer is listed, leaving little visible publishing redundancy for a package with no recent release activity. This increases continuity risk, though it is not severe on its own.
The repository has zero stars, forks, and watchers, providing no community activity or adoption evidence to offset the lack of maintenance. Popularity is supporting evidence, so this is a caution rather than the main risk.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This adds transparency risk for a library handling WeChat APIs and payments.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.