The source remains available and is not archived, with no install-time scripts. Licensing is inconsistent, so verify the terms before adoption.
55%
Total Score
50
63
100
A license file is present, but it is detected as Apache-2.0 while the manifest declares MIT. The package is licensed, yet the mismatch creates a concrete transparency concern.
The registry lists one maintainer, which creates a thin publishing base. The linked repository is owned by the same individual, so there is no broader organizational backing shown to offset that concentration.
The package has no README, tests, or changelog, leaving consumers with little usage guidance or verification material. Missing tests and changelog are normal in published artifacts, but the missing README matters for this library.
Only three releases exist since August 2022, with none in the last 12 months and the latest published about two years ago. This indicates weak ongoing maintenance for a library dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. The repository is still present, but there is no recent activity to compensate.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.