The small artifact is easy to inspect, has a clear MIT license, and matches its source repository. Its only release was over ten years ago, and the repository has not been pushed since 2016, making abandonment a serious concern.
38%
Total Score
64
75
The package has only one release, published over ten years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no indication of an active user or contributor base.
The repository is not archived, but its last push was in 2016, consistent with the registry's decade-long lack of releases. The non-archived status is a limited compensating signal, not evidence of active maintenance.
The repository has no security policy or security-scanning tooling reported, leaving vulnerability reporting and automated security hygiene undocumented. This is secondary to the much stronger maintenance concern.
The latest version is v0.1 rather than a stable major release, so consumers have little evidence of a mature compatibility policy. The absence of prerelease labeling does not compensate for the very early version.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.