The README, changelog, stable version, and small dependency set make the package straightforward to evaluate. Its proprietary license, single release, and no commits in the last three months leave long-term maintenance and reuse concerns.
58%
Total Score
50
100
86
75
The manifest declares a proprietary license, with no detected license text or license file. This permits some stated usage but is a real concern for an open-source dependency and limits transparency.
Only one registry account has publish access. Because the repository owner is an individual rather than an organization, the package has a thin visible publishing base.
This is a young package, about 110 days old, with only one release and no established release interval. That leaves little evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, this is meaningful evidence that maintenance may have paused.
The repository has no security policy. This is a transparency and response-process gap, though the package's small size and lack of workflow automation limit how heavily it weighs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twbs/bootstrap Version ^5 | — | — |
components/jquery Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.