The repository is tiny and has no tests, changelog, security scanning, or recent commits. It does have a recent release, a clear README, a matching repository, and no install scripts, but the license files identify AGPL-3.0 while the manifest declares GPL-3.0-or-later.
63%
Total Score
50
100
81
67
The manifest declares GPL-3.0-or-later and includes a license file, but the detected license text is AGPL-3.0. The mismatch requires resolving the actual licensing terms before adoption.
The artifact and repository have the same small, focused six-file tree, including a README, license, manifest, configuration, and source file. This is transparent but provides little evidence of broader engineering maturity.
The repository is owned by an individual user rather than an organization, so the small maintainer base represents limited visible project backing.
The repository had zero commits and zero active maintainers in the last 3 months. This is a concrete sign of weak current maintenance despite the recent registry release.
The repository has 1 star, 0 forks, and 2 watchers, indicating very limited independent adoption or review. Popularity is supporting evidence, but this adds to the thin maturity picture.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.