The four-file package offers little documentation, testing, or security process for consumers. MIT licensing, a repository that matches the package, and no install-time scripts reduce immediate adoption risk.
43%
Total Score
50
100
71
83
This package has only one release, published nearly 4 years and 10 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk.
The artifact has a README, but it is only 15 characters and provides no practical usage guidance. Missing tests and changelog files are normal for published artifacts; the GitHub release for this version is a small positive.
The repository recorded zero commits and zero active maintainers in the last 3 months, providing no evidence of current maintenance capacity.
The repository is not archived, which is a compensating signal, but it was last pushed over 3 years ago and therefore does not offset the inactive release history.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap rather than evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.