The repository is not archived and the package is not deprecated, avoiding the most severe adoption concerns. Its single maintainer and absent security tooling provide little compensation for the long inactivity and missing license.
38%
Total Score
50
57
83
The package has only one release, published in December 2021, with no releases in the last 12 months. This is strong evidence of an abandoned or minimally maintained dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap and indicating no observed maintenance.
Neither the package metadata nor the artifact or repository contains a recognized license. That creates a real adoption and legal-transparency gap.
The artifact has a README entry, but it is empty and provides no tests, changelog, or release notes. Missing tests and changelog are normal for published artifacts, while the empty README is a minor consumer-documentation gap.
The repository name does not match the package name, and the README could not be confirmed to mention the package. This raises some uncertainty about whether the linked repository is the package's actual project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.