The MIT license, included tests, and small dependency footprint make the package straightforward to inspect and adopt. The repository is not archived and has no install scripts, but its source relationship is not clearly identified.
38%
Total Score
50
64
75
The last registry release was about 13 years ago, with no releases in the past 12 months. This is strong evidence of abandonment despite the package having eight historical releases.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release hiatus. This materially raises maintenance risk.
The linked repository name does not match the package name and its README does not mention the package. Although this can occur with related repositories, ownership of this package is not clearly demonstrated.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no independent sign of an active user or contributor community.
The repository has no documented security policy. This is a transparency and reporting gap, especially for a package that has otherwise seen little recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.