I totally agree. I thought about adding a paragraph about how it seems like even oracle themself doesn’t use it on production (cause otherwise it’d have probably more downloads due to developers, CI, you name it) but it is possible they use a internal npm proxy with a cache.
Anyway it’s laughable that this package is the reason they base their argument on.