The package has a clear MIT license, a usable README, stable versioning, and no install-time scripts. Its source project shows no commits or releases for about six years, alongside minimal community activity, no security policy, and no README package mention.
45%
Total Score
50
72
83
The package has had no release in about six years, despite 10 releases overall and a previously regular cadence. This is strong evidence of abandonment risk for a dependency.
The repository had zero commits and zero active maintainers in the last three months, matching the long release gap. This materially increases abandonment risk.
There are no open issues or pull requests and no activity in the last month. This is consistent with a dormant project, although a quiet issue tracker alone is not severe.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent. Organization backing reduces concern somewhat, but the missing mention remains a caution.
The repository has zero stars, one fork, and three watchers. Low popularity is supporting evidence rather than decisive proof, but it provides little evidence of a broad support community.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.