Low project popularity and OpenSSF score are not enough to classify as malware. Insufficient evidence.
No verification record available.
The package's source project has low popularity and a low OpenSSF score, raising concerns about maintenance and community support. However, this single piece of evidence with low confidence is insufficient to classify it as malware.