The MIT license and release notes improve transparency. The linked project shows no recent commits, no security policy, and no clear reference to this package, leaving maintenance and ownership uncertain. Pinning this release would carry avoidable risk.
42%
Total Score
50
80
75
Only one registry maintainer is listed, providing a thin publishing base. The repository owner is an individual, so there is no observed organizational backing to compensate for that concentration.
The package has had no releases in the last 12 months, and its latest release was in November 2021. This indicates prolonged maintenance inactivity despite three total releases.
The repository recorded zero commits and zero active maintainers in the last three months. The lack of recent development materially increases abandonment risk.
The linked repository name does not match the package and its README does not mention the package. That weakens confidence that the repository is the package's authoritative source.
The repository has no security policy. For a package with no recent development activity, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.