The package has a clear Apache-2.0 license, no install-time scripts, and only one runtime dependency. Its brief documentation and absent security policy limit transparency, while the repository mismatch makes maintenance harder to verify.
38%
Total Score
0
100
63
75
Only one release exists, published about eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency expected to receive maintenance.
The repository has had zero commits and zero active maintainers in the last three months, following a last push in 2019. That confirms the long release gap is not just a registry publishing gap.
The repository name does not match the package name and its README does not mention the package, so ownership and ongoing maintenance of this package cannot be reliably verified from the linked source.
The linked repository has no security policy. That limits transparency about vulnerability reporting, though it is secondary to the much older release and commit history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.