It is MIT-licensed and has no install-time scripts. The repository is active and not archived, but validation and security processes are limited.
68%
Total Score
67
75
75
The artifact includes a README, while the absence of tests and a changelog is normal packaging practice and is not itself a gap here. The README is very short, so integration guidance is limited.
The package and repository are owned by the same individual account, so the matching ownership is consistent, but there is no organizational backing to offset the concentrated contributor activity.
The package is only 49 days old but already has 73 releases, with a median interval of about 1 minute. This shows active publishing but an unusually bursty and immature release process.
One contributor made about 87% of the recent commits, while the second made about 13%. The active second contributor partly offsets the concentration, but the project remains dependent on one primary contributor.
The repository name matches the package, but its README does not mention the package. This weakens the evidence that the repository clearly documents the published package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.