Usable with caveats: the package is licensed, tested in its repository, stable, and not deprecated, but version 1.2.1 has had no registry release for nearly five years. Recent repository activity and basic security tooling reduce abandonment concerns, though current commit activity is quiet and the workflow lacks explicit token permissions and a security policy.
64%
Total Score
50
100
94
67
The latest release was published nearly five years ago, with no releases in the last 12 months, which is a meaningful maintenance concern for a dependency. The repository was pushed recently, so the project is not clearly abandoned, but that activity has not produced a new registry release.
There were no commits from active maintainers in the last three months, so ongoing maintenance is currently uncertain despite the repository's recent push timestamp.
No security policy is present, leaving vulnerability reporting and response expectations undocumented.
The sole workflow has no top-level token permissions declaration, so its GitHub Actions permissions are less explicit than recommended.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.