The package has a clear README, tests, MIT licensing, and only one runtime dependency. Its single-user ownership and absent security policy provide limited evidence of ongoing support for new issues.
58%
Total Score
50
100
90
75
The registry lists one publishing maintainer, xwx. The repository is owned by an individual rather than an organization, so there is little visible maintainer redundancy if that person stops supporting the package.
The latest release was published in July 2020, with no releases in the last 12 months, despite the package having four releases over roughly nine years. This is a meaningful maintenance concern, though the stable v1.2.1 release and documented release notes provide some maturity evidence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no release activity since July 2020. This raises abandonment risk.
The linked repository has no security policy. For a small utility this is not disqualifying, but it reduces transparency about how vulnerability reports would be handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.